API Authentication Flaw in PraisonAI Multi-Agent Teams System
CVE-2026-55538

7.3HIGH

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-55538?

PraisonAI, a multi-agent teams system, has a critical flaw in its API authentication process. Prior to version 4.6.51, the application improperly handled configuration settings for the 'api_key', allowing unauthorized agents to execute actions without proper authentication. Specifically, the methods for creating agents did not require valid bearer tokens or X-API-Key values for POST requests to /agents or /agents/{agent_name}. This oversight could lead to exposure and exploitation of sensitive functionalities by malicious users. The issue has been resolved in version 4.6.58, where enhanced authentication measures are implemented to prevent such unauthorized access.

Affected Version(s)

PraisonAI < 4.6.58

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.