Object-Level Authorization Flaw in PraisonAI Platform Affects Workspace Data Security
CVE-2026-47399

8.8HIGH

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47399?

The PraisonAI Platform suffers from an object-level authorization flaw that allows authenticated users to access and manipulate data across different workspaces. Specifically, prior to version 0.1.4, the platform's workspace-scoped REST routes did not enforce proper isolation checks. This design flaw enabled users to bypass workspace boundaries by utilizing the global UUID of objects belonging to other workspaces. As such, a member of one workspace could exploit this vulnerability to perform unauthorized operations on items from another workspace, leading to potential data breaches and unauthorized modifications.

Affected Version(s)

praisonai-platform < 0.1.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.