Authentication Bypass in PraisonAI Multi-Agent Teams System
CVE-2026-55533

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-55533?

PraisonAI, a multi-agent teams system, contains a flaw prior to version 4.6.58 where the create_auth_middleware() function allows unauthenticated requests when api-key authentication is not provided or if JWT authentication is missing the required PRAISONAI_JWT_SECRET. This vulnerability permits an externally connected Recipe server to accept unauthorized POST requests to /v1/recipes/run even when authentication measures are ostensibly in place. It is crucial for users of the affected versions to upgrade to version 4.6.58 to mitigate this issue.

Affected Version(s)

PraisonAI < 4.6.58

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.