CVE-2026-57127

CRITICAL Status: Received

CVSS Scores

CVSS v3.x Base Score
9.8
CRITICAL

Description

PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KEY or PRAISONAI_JWT_SECRET and the corresponding recipe value are absent. Unauthenticated clients can then reach recipe execution, input, and output surfaces and may trigger connected tools despite the operator explicitly enabling authentication. This issue is fixed in 4.6.58.

Published
September 14, 2026 4:17 PM
Last Modified
September 14, 2026 5:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-306 CWE-1188

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.