CVE-2026-79916 | 1Panel-dev MaxKB up to 2.10.4 Credentials Parsing /root/.aws/credentials _update_aws_credentials access_key_id/secret_access_key os command injection
A vulnerability was found in 1Panel-dev MaxKB up to 2.10.4. It has been declared as critical. The affected element is the function _update_aws_credentials of the file /root/.aws/credentials of the component Credentials Parsing. Such manipulation of the argument access_key_id/secret_access_key leads to os command injection.
This vulnerability is referenced as CVE-2026-79916. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More