← Terug naar overzicht

CVE-2026-55538 affects PraisonAI, a multi-agent teams system, prior to version 4.6.51. The vulnerability exists because the _create_agents_app() function fails to enforce authentication on POST /agents and POST /agents/{agent_name} endpoints, despite the system parsing an API key from config. As a result, requests with missing or incorrect bearer tokens or X-API-Key headers are still processed and reach agent execution. This constitutes a broken authentication vulnerability that could allow unauthorized actors to interact with and execute agents without valid credentials. The issue has been patched in version 4.6.58 of PraisonAI. Users are advised to upgrade immediately to mitigate the risk of unauthorized agent access and potential misuse of the multi-agent system.

Affected products

  • PraisonAI

Related CVE's

  • CVE-2026-55538

Categories

  • Emerging Technologies
  • Identity & Access
  • Web Technologies