Access Control Flaw in PraisonAI Platform by PraisonAI
CVE-2026-47407

9.4CRITICAL

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47407?

The PraisonAI Platform has a critical configuration flaw in its access control mechanisms that permits malicious actors to exploit workspace identifiers and UUIDs to gain unauthorized access to resources of other workspaces. This occurs through an insufficient validation of resource IDs in conjunction with the workspace ID in URL paths, allowing users to interact with resources outside of their intended scope. Furthermore, inherent deficiencies in role management enable lower-tier members to elevate their privileges, modifying roles and manipulating workspace memberships without appropriate checks. The platform, which lacks adequate registrational safeguards such as email verification and exposes sensitive endpoints by default, requires immediate attention to fortify its security posture against such vulnerabilities. This issue has been addressed in version 0.1.4.

Affected Version(s)

praisonai-platform < 0.1.4

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.