Skip to content
PraisonAI Framework Vulnerability Allows Unauthenticated Access

PraisonAI Framework Vulnerability Allows Unauthenticated Access

First seen 30 Sep 2026, 14:29 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 17:31 UTC
  • •CVE-2026-44338 allows unauthenticated access to PraisonAI endpoints.
  • •The vulnerability was exploited within hours of its disclosure on May 11, 2026.
  • •Affected versions include PraisonAI 2.5.6 through 4.6.33, with no immediate patch available.

On May 11, 2026, a vulnerability (CVE-2026-44338) was disclosed in the PraisonAI multi-agent orchestration framework, which shipped with authentication disabled by default. This flaw, with a CVSS score of 7.3, allows any user to access sensitive endpoints like /agents and /chat without authentication. The vulnerability stems from hard-coded variables in the legacy Flask API server, specifically in src/praisonai/api_server.py, where AUTH_ENABLED is set to False. Within hours of the advisory, automated scanners began probing for vulnerable instances, confirming the ease of access to these endpoints. The flaw affects versions 2.5.6 through 4.6.33 of the framework. Experts warn that organizations using this framework without proper security measures are at risk of unauthorized access and potential exploitation. The vulnerability highlights a concerning trend of insecure defaults in AI orchestration tools, emphasizing the need for rigorous security practices.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-08
CVE-2026-44338 published
A critical vulnerability in PraisonAI's framework was disclosed, allowing unauthenticated access.
github.com
2026-05-11
First exploitation attempt observed
Automated scanners began probing for the vulnerability within hours of its public disclosure.
Forkast.News
2026-09-30
Current status reported
The vulnerability remains unpatched, with ongoing concerns about its impact on AI orchestration security.
Forkast.News

More articles in this cluster (3)

Following this threat?

Track Carbonato, Black Duck and CVE-2026-44338 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of PraisonAI are affected?
Versions 2.5.6 through 4.6.33 are affected by this vulnerability.
Is there a patch available for this vulnerability?
As of now, there is no patch available for CVE-2026-44338.
What should organizations do to mitigate this risk?
Organizations should audit their configurations and ensure that authentication is enabled for all deployed instances.