CVE-2026-39420 | 1Panel-dev MaxKB up to 2.7.x Tool Debug API sandbox.so LD_PRELOAD protection mechanism (GHSA-7wgv-v2r3-7f7w)
A vulnerability labeled as critical has been found in 1Panel-dev MaxKB up to 2.7.x. The affected element is an unknown function of the file sandbox.so of the component Tool Debug API. Executing a manipulation of the argument LD_PRELOAD can lead to protection mechanism failure.
This vulnerability is registered as CVE-2026-39420. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.