{"id":917,"date":"2026-05-14T12:15:59","date_gmt":"2026-05-14T12:15:59","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=917"},"modified":"2026-05-14T12:15:59","modified_gmt":"2026-05-14T12:15:59","slug":"praisonai-cve-2026-44338-auth-bypass-targeted-within-hours-of-disclosure","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=917","title":{"rendered":"PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">May 14, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ API Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg2IaSkdVZD_wyJJT-sODoazviDXhw3MGkn5XHYocnTL1YfLJpgJ-1wNaAm0Rk0phyrIv8vS73SNNkPSmlxRkK9ySAQGnn_tCP9JcVKyqee6lxjlYEp0cs2C_R9cDtgCEXwsjWtx1XnafF5r_fAuDDAvg0CRMOgJk8ZMwSjRsw1Js90uR-97t-rh5yU12Oj\/s1700-e365\/praison.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Threat actors have been observed <a href=\"https:\/\/www.sysdig.com\/blog\/cve-2026-44338-praisonai-authentication-bypass-in-under-4-hours-and-the-growing-trend-of-rapid-exploitation\">attempting to exploit<\/a> a recently disclosed security vulnerability in <b>PraisonAI<\/b>, an open-source multi-agent orchestration framework, within four hours of public disclosure.<\/p>\n<p>The vulnerability in question is <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-44338\">CVE-2026-44338<\/a> (CVSS score: 7.3), a case of missing authentication that exposes sensitive endpoints to anyone, potentially allowing an attacker to invoke the API server&#8217;s protected functionality without a token.\u00a0<\/p>\n<p>\u00ab<a href=\"https:\/\/github.com\/MervinPraison\/PraisonAI\">PraisonAI<\/a> ships a legacy Flask API server with authentication disabled by default,\u00bb according to an <a href=\"https:\/\/github.com\/advisories\/GHSA-6rmh-7xcm-cpxj\">advisory<\/a> released by the maintainers earlier this month. \u00abWhen that server is used, any caller that can reach it can access \/agents and trigger the configured agents.yaml workflow through \/chat without providing a token.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Specifically, the legacy Flask-based API server, src\/praisonai\/api_server.py, hard-codes AUTH_ENABLED = False and AUTH_TOKEN = None. According to PraisonAI, successful exploitation of the flaw can have varied impacts, including &#8211;<\/p>\n<ul>\n<li>Unauthenticated enumeration of the configured agent file through \/agents<\/li>\n<li>Unauthenticated triggering of the locally configured \u00abagents.yaml\u00bb workflow through \/chat<\/li>\n<li>Repeated consumption of the model\/API quota, and<\/li>\n<li>Exposure of the results of PraisonAI.run() to the unauthenticated caller<\/li>\n<\/ul>\n<p><a name=\"more\"\/><\/p>\n<p>\u00abThe impact therefore, depends on what the operator&#8217;s agents.yaml is allowed to do, but the authentication bypass is unconditional in the shipped legacy server,\u00bb PraisonAI said.<\/p>\n<p>The vulnerability affects all versions of the Python package from 2.5.6 through 4.6.33. It has been patched in version 4.6.34. Security researcher Shmulik Cohen has been credited with discovering and reporting the bug.<\/p>\n<p>In a report published by Sysdig this week, the cloud security company said it observed attempts to exploit the flaw within hours of it becoming public knowledge.<\/p>\n<p>\u00abWithin three hours and 44 minutes of the advisory becoming public, a scanner identifying itself as CVE-Detector\/1.0 was probing the exact vulnerable endpoint on internet-exposed instances,\u00bb it said. \u00abThe advisory was published [on May 11, 2026,] at 13:56 UTC. The first targeted request landed at 17:40 UTC the same day.\u00bb<\/p>\n<p>The activity, per Sysdig, originated from the IP address 146.190.133[.]49 and followed a packaged-scanner profile that carried out two passes spaced eight minutes apart, with each pass pushing approximately 70 requests in roughly 50 seconds.<\/p>\n<p>While the first pass scanned generic disclosure paths (\/.env, \/admin, \/users\/sign_in, \/eval, \/calculate, \/Gemfile.lock), the second pass specifically singled out AI-agent surfaces, including PraisonAI.<\/p>\n<p>\u00abThe probe that matched CVE-2026-44338 directly was a single GET \/agents with no Authorization header and User-Agent CVE-Detector\/1.0,\u00bb Sysdig said. \u00abThat request returns 200 OK with body {\u00abagent_file\u00bb:\u00bbagents.yaml\u00bb,\u00bbagents\u00bb:[&#8230;]}, confirming the bypass was successful.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The scanner has not been found to send any POST request to the \u00ab\/chat\u00bb endpoint during either pass, indicating the activity is consistent with an initial check to determine if the auth bypass works and confirm if the host is exploitable via CVE-2026-44338.<\/p>\n<p>The rapid exploitation of the PraisonAI is the latest example of a broader trend where threat actors are increasingly adopting newly disclosed flaws into their arsenal before they can be patched. Users are advised to apply the latest fixes as soon as possible, audit existing deployments, review model provider billing for any suspicious activity, and rotate credentials referenced in \u00abagents.yaml.\u00bb<\/p>\n<p>\u00abAdversary tooling has scaled to the entire AI and agent ecosystem &#8212; no matter the size, and not just the household names \u2013 and the operating assumption for any project that ships an unauthenticated default must be that the window between disclosure and active exploitation is measured in single-digit hours,\u00bb Sysdig said.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802May 14, 2026Vulnerability \/ API Security Threat actors have been observed attempting to exploit a recently disclosed security vulnerability in PraisonAI, an open-source multi-agent orchestration framework, within four hours&hellip;<\/p>\n","protected":false},"author":1,"featured_media":918,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1672,394,1671,799,582,1670,113],"class_list":["post-917","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-auth","tag-bypass","tag-cve202644338","tag-disclosure","tag-hours","tag-praisonai","tag-targeted"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/917","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=917"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/917\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/918"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=917"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=917"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=917"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}