github.com PraisonAI Framework Vulnerability Allows Unauthenticated Access
Article Content
- •CVE-2026-44338 allows unauthenticated access to PraisonAI endpoints.
- •The vulnerability was exploited within hours of its disclosure on May 11, 2026.
- •Affected versions include PraisonAI 2.5.6 through 4.6.33, with no immediate patch available.
On May 11, 2026, a vulnerability (CVE-2026-44338) was disclosed in the PraisonAI multi-agent orchestration framework, which shipped with authentication disabled by default. This flaw, with a CVSS score of 7.3, allows any user to access sensitive endpoints like /agents and /chat without authentication. The vulnerability stems from hard-coded variables in the legacy Flask API server, specifically in src/praisonai/api_server.py, where AUTH_ENABLED is set to False. Within hours of the advisory, automated scanners began probing for vulnerable instances, confirming the ease of access to these endpoints. The flaw affects versions 2.5.6 through 4.6.33 of the framework. Experts warn that organizations using this framework without proper security measures are at risk of unauthorized access and potential exploitation. The vulnerability highlights a concerning trend of insecure defaults in AI orchestration tools, emphasizing the need for rigorous security practices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Carbonato, Black Duck and CVE-2026-44338 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of PraisonAI are affected?
Is there a patch available for this vulnerability?
What should organizations do to mitigate this risk?
Continue Reading
CARBONATO Botnet Exploits Exposed Docker APIs Using AI Agents The CARBONATO botnet, discovered by ThreatDown, targets exposed Docker daemons on port 2375 without authentication, enabling attackers to install the Hermes Agent AI framework. This malware has been active since at least October 2024 and has been linked to a publicly accessible container registry containing 59…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…