← Terug naar overzicht

CVE-2026-55528 affects PraisonAI, a multi-agent teams system, in versions prior to praisonaiagents 1.6.58. The vulnerability exists because AgentServer exposes ServerConfig.auth_token but the _create_app method fails to enforce authentication checks on any route. This allows remote unauthenticated callers to subscribe, publish, and perform other sensitive actions without providing a valid bearer token or X-Auth-Token header, even when authentication is explicitly configured. The flaw represents a complete authentication bypass in the AgentServer component. The issue has been resolved in praisonaiagents version 1.6.58. Users are strongly advised to upgrade immediately to mitigate the risk of unauthorized access to their multi-agent systems.

Affected products

  • PraisonAI praisonaiagents < 1.6.58

Related CVE's

  • CVE-2026-55528

Categories

  • Emerging Technologies
  • Identity & Access
  • Web Technologies