PraisonAI CVE-2026-44338 Exploited in the Wild Hours After Patch Disclosure
ID: e4659247-3f79-5ff2-9086-3222e150d6a8
STIX ID: report--e4659247-3f79-5ff2-9086-3222e150d6a8
Feed Name: securityonline.info
Sysdig Threat Research reports that CVE-2026-44338 — an authentication-bypass in PraisonAI's legacy api_server.py — was exploited in the wild 3 hours 44 minutes after disclosure; attackers and scanners (identified by a DigitalOcean IP and User-Agent "CVE-Detector/1.0") accessed GET/agents and POST/chat endpoints to retrieve agent configs and trigger workflows, enabling data exposure, credential misuse, and model API billing abuse; maintainers recommend immediate patching to 4.6.34+, decommissioning the legacy entrypoint, and auditing/rotating credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
