A vulnerability classified as problematic was found in 1Panel-dev MaxKB up to 2.10.4-lts. This impacts the function UpdateStoreTool.update_tool of the component UpdateStoreTool. The manipulation of the argument download_url/download_callback_url results in open redirect.

This vulnerability was named CVE-2026-64870. The attack may be performed from remote. There is no available exploit.