logo

PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure

ID: 39d072da-04f8-53eb-9afe-ffffff040fea

STIX ID: report--39d072da-04f8-53eb-9afe-ffffff040fea

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: [email protected] (The Hacker News)

...
...

A critical authentication-bypass vulnerability (CVE-2026-44338, CVSS 7.3) in PraisonAI's legacy Flask API server (AUTH_ENABLED = False) allowed unauthenticated callers to enumerate configured agents and trigger workflows; the flaw affected versions 2.5.6 through 4.6.33 and was patched in 4.6.34. Sysdig observed active exploitation attempts within hours of disclosure—scanner requests from 146.190.133.49 using User-Agent CVE-Detector/1.0 performed GET /agents, returned agent_file data, and confirmed the bypass—prompting advice to patch, audit deployments, and rotate credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.