{"id":245864,"date":"2026-05-14T07:40:00","date_gmt":"2026-05-14T11:40:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/05\/14\/praisonai-cve-2026-44338-auth-bypass-targeted-within-hours-of-disclosure\/"},"modified":"2026-05-14T10:45:07","modified_gmt":"2026-05-14T14:45:07","slug":"praisonai-cve-2026-44338-auth-bypass-targeted-within-hours-of-disclosure","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/05\/14\/praisonai-cve-2026-44338-auth-bypass-targeted-within-hours-of-disclosure\/","title":{"rendered":"PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/praisonai-cve-2026-44338-auth-bypass.html\">PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/praisonai-cve-2026-44338-auth-bypass.html\">https:\/\/thehackernews.com\/2026\/05\/praisonai-cve-2026-44338-auth-bypass.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-14 07:40:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">May 14, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ API Security<\/span><\/p>\n<p>Threat actors have been observed attempting to exploit a recently disclosed security vulnerability in PraisonAI, an open-source multi-agent orchestration framework, within four hours of public disclosure.<\/p>\n<p>The vulnerability in question is CVE-2026-44338 (CVSS score: 7.3), a case of missing authentication that exposes sensitive endpoints to anyone, potentially allowing an attacker to invoke the API server&#8217;s protected functionality without a token.\u00a0<\/p>\n<p>&#8220;PraisonAI ships a legacy Flask API server with authentication disabled by default,&#8221; according to an advisory released by the maintainers earlier this month. &#8220;When that server is used, any caller that can reach it can access \/agents and trigger the configured agents.yaml workflow through \/chat without providing a token.&#8221;<\/p>\n<p>Specifically, the legacy Flask-based API server, src\/praisonai\/api_server.py, hard-codes AUTH_ENABLED = False and AUTH_TOKEN = None. According to PraisonAI, successful exploitation of the flaw can have varied impacts, including &#8211;<\/p>\n<ul>\n<li>Unauthenticated enumeration of the configured agent file through \/agents<\/li>\n<li>Unauthenticated triggering of the locally configured &#8220;agents.yaml&#8221; workflow through \/chat<\/li>\n<li>Repeated consumption of the model\/API quota, and<\/li>\n<li>Exposure of the results of PraisonAI.run() to the unauthenticated caller<\/li>\n<\/ul>\n<p>&#8220;The impact therefore, depends on what the operator&#8217;s agents.yaml is allowed to do, but the authentication bypass is unconditional in the shipped legacy server,&#8221; PraisonAI said.<\/p>\n<p>The vulnerability affects all versions of the Python package from 2.5.6 through 4.6.33. It has been patched in version 4.6.34. Security researcher Shmulik Cohen has been credited with discovering and reporting the bug.<\/p>\n<p>In a report published by Sysdig this week, the cloud security company said it observed attempts to exploit the flaw within hours of it becoming public knowledge.<\/p>\n<p>&#8220;Within three hours and 44 minutes of the advisory becoming public, a scanner&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/praisonai-cve-2026-44338-auth-bypass.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure https:\/\/thehackernews.com\/2026\/05\/praisonai-cve-2026-44338-auth-bypass.html Publish Date: 2026-05-14 07:40:00 Source&#8230;<\/p>\n","protected":false},"author":1,"featured_media":245865,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg2IaSkdVZD_wyJJT-sODoazviDXhw3MGkn5XHYocnTL1YfLJpgJ-1wNaAm0Rk0phyrIv8vS73SNNkPSmlxRkK9ySAQGnn_tCP9JcVKyqee6lxjlYEp0cs2C_R9cDtgCEXwsjWtx1XnafF5r_fAuDDAvg0CRMOgJk8ZMwSjRsw1Js90uR-97t-rh5yU12Oj\/s1600\/praison.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[31,27],"class_list":["post-245864","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-exploit","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/245864"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=245864"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/245864\/revisions"}],"predecessor-version":[{"id":245867,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/245864\/revisions\/245867"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/245865"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=245864"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=245864"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=245864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}