CVE-2026-44338Active Exploitation(praison / praisonai)

HIGHCVSS 7.3 · HIGH

Exploitation observed; activity peaked at 21 mentions and remains active

Immediate actions

  • Patch praison praisonai systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication disabled by default. When that server is used, any caller that can reach it can access /agents and trigger the configured agents.yaml workflow through /chat without providing a token. This issue has been patched in version 4.6.34.

6.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-668CWE-1188

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai

Threat summary

  • Active exploitation appears in 49 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 62 mentions across 19 observed days

What's happening

  • Active exploitation reported across 49 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 18 signals
  • Technical details provided in 43 signals
  • General: 5 classified signals
  • Peaked 15d ago at 21 mentions (2026-05-14); latest day: 1
  • 62 total mentions across 19 days

Affected systems

Vendors
Products
praisonai

Deep dive

Activity timeline62 mentions / 19d
05111621Mentions · 2026-05-08: 1Mentions · 2026-05-12: 1Mentions · 2026-05-13: 6Mentions · 2026-05-14: 21Mentions · 2026-05-15: 6Mentions · 2026-05-16: 5Mentions · 2026-05-17: 1Mentions · 2026-05-18: 5Mentions · 2026-05-19: 1Mentions · 2026-05-21: 2Mentions · 2026-05-22: 2Mentions · 2026-05-23: 1Mentions · 2026-05-26: 1Mentions · 2026-05-27: 3Mentions · 2026-06-11: 1Mentions · 2026-06-12: 1Mentions · 2026-07-21: 2Mentions · 2026-07-25: 1Mentions · 2026-08-20: 1PoC Mentioned / Linked · 2026-05-16: 1PoC Mentioned / Linked · 2026-05-18: 1Active Exploitation · 2026-05-12: 1Active Exploitation · 2026-05-13: 6Active Exploitation · 2026-05-14: 17Active Exploitation · 2026-05-15: 6Active Exploitation · 2026-05-16: 4Active Exploitation · 2026-05-17: 1Active Exploitation · 2026-05-18: 4Active Exploitation · 2026-05-19: 1Active Exploitation · 2026-05-21: 2Active Exploitation · 2026-05-22: 2Active Exploitation · 2026-05-23: 1Active Exploitation · 2026-05-27: 1Active Exploitation · 2026-06-11: 1Active Exploitation · 2026-06-12: 1Active Exploitation · 2026-07-25: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 3Patch / Workaround · 2026-05-14: 4Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-05-18: 3Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-21: 2Patch / Workaround · 2026-05-22: 1Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 4Technical Details · 2026-05-14: 15Technical Details · 2026-05-15: 3Technical Details · 2026-05-16: 3Technical Details · 2026-05-17: 1Technical Details · 2026-05-18: 4Technical Details · 2026-05-19: 1Technical Details · 2026-05-21: 2Technical Details · 2026-05-22: 2Technical Details · 2026-05-23: 1Technical Details · 2026-05-26: 1Technical Details · 2026-06-11: 1Technical Details · 2026-06-12: 1Technical Details · 2026-07-25: 1Technical Details · 2026-08-20: 105-0805-1205-1305-1405-1505-1605-1705-1805-1905-2105-2205-2305-2605-2706-1106-1207-2107-2508-20
Signal classification4 categories
Active Exploitation
4775.8%
Patch
69.7%
General
58.1%
Disclosure
46.5%
Referenced assets30 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-081
Disclosure1
2026-05-121
Active Exploitation1
2026-05-136
Active Exploitation6
2026-05-1421
Active Exploitation17Disclosure1Patch3
2026-05-156
Active Exploitation6
2026-05-165
Active Exploitation4General1
2026-05-171
Active Exploitation1
2026-05-185
Active Exploitation4Disclosure1
2026-05-191
Patch1
2026-05-212
Active Exploitation2
2026-05-222
Active Exploitation1Patch1
2026-05-231
Active Exploitation1
2026-05-261
Patch1
2026-05-273
Active Exploitation1General2
2026-06-111
Active Exploitation1
2026-06-121
Active Exploitation1
2026-07-212
General2
2026-07-251
Active Exploitation1
2026-08-201
Disclosure1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Threat actors targeted PraisonAI CVE-2026-44338, an authentication bypass vulnerability, within hours of disclosure. The flaw affects versions 2.5.6–4.6.33 and can expose the /agents endpoint without authorization. Read the full report: https://thehackernews.com/2026/05/praisonai-cve-2026-44338-auth-bypass.html

    Post summary

    The report confirms that threat actors actively exploited CVE-2026-44338 within hours of its disclosure, highlighting an authentication bypass that exposes the /agents endpoint in certain PraisonAI versions.

    3813849.0K
    1.9M followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Sysdig warns: PraisonAI (CVE-2026-44338) exploited in under 4 hours. Attackers bypassed auth to hijack agents and drain API quotas. Update to 4.6.34 now! #PraisonAI #CyberSecurity #InfoSec #AISecurity #VulnerabilityAlert #CVE202644338 #ExploitAlert https://securityonline.info/praisonai-vulnerability-cve-2026-44338-exploited-in-the-wild/ https://t.co/UzGuHpfU6R

    Post summary

    Sysdig warns that PraisonAI CVE‑2026‑44338 was actively exploited within 4 hours, with attackers bypassing authentication to hijack agents and drain API quotas; upgrading to 4.6.34 is recommended.

    04072566
    12.5K followersView on X
  • Sysdig@sysdig
    Active Exploitation

    3 hours. 44 minutes. That's how long it took for active scanning to start after CVE-2026-44338 dropped. Advisory-to-exploitation windows are now measured in single-digit hours. Every AI project is a target. Full research from Sysdig TRT: https://okt.to/wiS9LD   #CloudSecurity #ThreatResearch #AIAgents

    Post summary

    The message highlights that CVE-2026-44338 began being actively exploited only about 3.5 hours after disclosure, underscoring the rapid exploitation risk for AI-focused projects.

    12081485
    10.3K followersView on X
  • TodayInCyber@TodayInCyberIO
    Active Exploitation

    🔴 CRITICAL | Threat actors have been observed exploiting CVE-2026-44338, a critical authentication bypass vulnerability in the PraisonAI open-source multi-agent orchestration framework, within four hours of i… #vulnerability #CVE202644338 #cybersecurity https://todayincyber.io/feed/vulnerability/article/019e2670-d471-7860-b133-03b65850b166

    Post summary

    Threat actors have exploited CVE-2026-44338 within hours of its public disclosure; no PoC, exploit code, patch, or false‑positive claim is provided, and the vulnerability is described as a critical authentication bypass.

    03050145
    10 followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Critical flaw CVE-2026-44338 in PraisonAI exposes autonomous workflows to unauthenticated hijackers within hours of disclosure. Update to v4.6.34 immediately! #PraisonAI #CVE202644338 #AISecurity2026 #InfoSec #BugBounty #DevSecOps #AIAgents https://meterpreter.org/critical-pre-auth-flaw-cve-2026-44338-exploited-to-hijack-autonomous-ai-agents/ https://t.co/1NnNMUVsVs

    Post summary

    The tweet announces that CVE‑2026‑44338 is being actively exploited within hours of disclosure, urges an immediate patch to version 4.6.34, and includes a link likely pointing to a PoC or exploit details.

    01051655
    12.5K followersView on X
  • connect24h@connect24h
    Active Exploitation

    「公開4時間以内に悪用」AIエージェントフレームワーク PraisonAI で認証バイパス脆弱性(CVE-2026-44338、CVSS 7.3)が発覚。開示からわずか4時間未満で攻撃者が動き出した。AIインフラが直接標的になる時代、従来のパッチウィンドウ前提は崩壊 https://is.gd/KTeB08 #AIセキュリティ #CSIRT

    Post summary

    The report indicates that PraisonAI’s authentication bypass vulnerability (CVE‑2026‑44338, CVSS 7.3) was actively exploited within four hours of disclosure, underscoring the urgency of addressing AI infrastructure security.

    01011329
    4.6K followersView on X
  • CyberSecurity88@CSec88
    Active Exploitation

    New AI Security Warning: PraisonAI Vulnerability Targeted in Under 4 Hours Attackers started targeting a newly disclosed AI vulnerability in under 4 hours. #CyberSecurity #AIsecurity #ThreatIntelligence Full Story 👉 https://cybersecurity88.com/news/praisonai-cve-2026-44338-exploited-within-hours-after-public-disclosure/ https://t.co/zg86VEBTeN

    Post summary

    A newly disclosed PraisonAI vulnerability was reportedly exploited within four hours of its public disclosure, indicating rapid attacker interest and active exploitation.

    00030118
    546 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-44338 exploited in under 4 hours: PraisonAI authentication bypass demonstrates AI-accelerated exploitation becoming the norm. Scanner labeled CVE-Detector/1.0 probing vulnerable endpoints just 3h44m after GitHub advisory. Key technical details: • CVE-2026-44338 (CVSS not specified): Hard-coded AUTH_ENABLED=False in api_server.py exposes GET /agents and POST /chat endpoints • All PyPI releases ≤4.6.33 vulnerable - authentication fails open by design in check_auth() function • Scanner from 146[.]190[.]133[.]49 targeted exact vulnerable paths, confirming successful bypass with 200 OK responses • POST /chat triggers PraisonAI().run() regardless of message content - impact depends on configured agents.yaml workflow Attack methodology: • Two-pass scanning: generic disclosure paths first, then AI-agent specific endpoints • User-Agent "CVE-Detector/1.0" serves as reliable IOC across any targeted infrastructure • Validation-focused approach: enumerate agents, confirm bypass, log as exploitable, move to next target DFIR artifacts: • Network logs showing unauthenticated requests to /agents and /chat without Authorization headers • Python subprocess spawning and unexpected network egress from agent processes post-exploitation • Access attempts to Python fingerprint paths: /pyproject.toml, /poetry.lock, /requirements.txt Deploy WAF rules blocking unauthenticated access to /agents and /chat endpoints. Hunt for User-Agent "CVE-Detector/1. #DFIR_Radar

    Post summary

    CVE‑2026‑44338 was actively exploited within 4 hours, with an authentication bypass via hard‑coded settings in PraisonAI’s api_server.py, and WAF rules are recommended as a mitigation.

    11010252
    1.8K followersView on X
  • Blue Team News@blueteamsec1
    Active Exploitation

    PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure http://dlvr.it/TTjFwg #PraisonAI #CVE202644338 #AuthBypass #CyberSecurity #Vulnerability https://t.co/CqLL8FGKyG

    Post summary

    An authorization bypass vulnerability (CVE‑2026‑44338) in PraisonAI was reportedly targeted within hours of its public disclosure, indicating active exploitation in the wild.

    000111.8K
    56.7K followersView on X
  • Jim Nitterauer 🇺🇸@JNitterauer
    Active Exploitation

    ⏱️ 3hrs 44min. That's how fast CVE-2026-44338 in PraisonAI was exploited after disclosure. AI platforms are the new attack surface. Patch & isolate your AI tools NOW. #AIsecurity #cybersecurity https://thehackernews.com/2026/05/praisonai-cve-2026-44338-auth-bypass.html

    Post summary

    CVE-2026-44338 in PraisonAI was actively exploited within hours of disclosure, prompting a call for immediate patching and isolation of AI tools.

    0002082
    8.5K followersView on X
  • Rock Lambros@rocklambros
    General

    Sysdig research found CVE-2026-44338 in the PraisonAI framework was probed by scanners 3 hours, 44 minutes, and 39 seconds after disclosure. Palo Alto Networks reports 28.3% of CVEs are now exploited within 24 hours. AI-assisted exploit development operates at scale.

    Post summary

    The tweet notes a vulnerability (CVE‑2026‑44338) was probed shortly after disclosure and cites a general exploitation statistic, without providing technical details, patches, or evidence of active exploitation.

    1001074
    734 followersView on X
  • Kwame@kwame_nyx
    Active Exploitation

    Two pieces of AI agent security data published this week: → CVE-2026-44338 dropped on PraisonAI (May 14). The legacy Flask API server hardcodes AUTH_ENABLED = False. Any caller on the network invokes agent workflows. The Hacker News reports the vulnerability was targeted within hours of disclosure. → Akeyless surveyed 400 IT/security leaders running AI agents (May 12). 67% suspect their agents have already accessed unauthorized data. Only 7% believe their controls would prevent a compromised agent from operating. One root cause: the identity layer for AI agents doesn't yet exist as an open standard. Vorim AI is building that layer. cryptographic identity per agent, scoped permissions, signed audit trail.

    Post summary

    CVE‑2026‑44338 was disclosed and quickly exploited, targeting the Flask API that had AUTH_ENABLED set to false, while no patch or exploit code is publicly referenced.

    1001070
    60 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🚨 New auth bypass alert: CVE-2026-44338 in PraisonAI lets attackers potentially skip authentication and reach sensitive functionality. Review your deployment, patch fast, and check exposed AI agent workflows now. #CVE202644338 #PraisonAI #CyberSecurity #AppSec #InfoSec #AIsecurity

    Post summary

    A new authentication bypass vulnerability (CVE-2026-44338) affects PraisonAI, urging users to review deployments and patch promptly to prevent potential unauthorized access to sensitive AI agent workflows.

    1001062
    1.3K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure https://thehackernews.com/2026/05/praisonai-cve-2026-44338-auth-bypass.html

    Post summary

    CVE-2026-44338 in PraisAI enables authentication bypass and was reportedly targeted within hours of its public disclosure.

    000111.1K
    158.6K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Active Exploitation

    PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure https://thehackernews.com/2026/05/praisonai-cve-2026-44338-auth-bypass.html?m=1

    Post summary

    The brief text indicates that CVE-2026-44338 is being actively exploited shortly after disclosure, but lacks details on PoC, tools, patches, or technical specifics.

    00002265
    10.5K followersView on X
  • SoEmailSecurity@Soemailsecurity
    Active Exploitation

    Threat actors exploited PraisonAI's CVE-2026-44338 auth bypass vulnerability just 4 hours after disclosure, what's your team's plan to respond that quickly to emerging threats? #cybersecurity #vulnerabilitymanagement #PraisonAI

    Post summary

    Threat actors exploited PraisonAI’s CVE‑2026‑44338, an authentication bypass vulnerability, within hours of its disclosure, indicating active exploitation in the wild.

    1001043
    60 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 High - PraisonAI Legacy API Authentication Bypass (CVE-2026-44338) PraisonAI ships a legacy Flask API server with authentication disabled by default, allowing unauthenticated access to /agents and workflow execution through /chat. A remote attacker can trigger configured agents.yaml workflows without a token, potentially leading to unauthorized agent execution, workflow abuse, and API quota consumption. 👉 Affected: PraisonAI >= 2.5.6 <= 4.6.33 | Fix: Upgrade to 4.6.34 and avoid exposing legacy API deployments without authentication

    Post summary

    CVE‑2026‑44338 is a high‑severity authentication bypass in PraisonAI’s legacy Flask API, permitting unauthenticated workflow execution; users are advised to upgrade to version 4.6.34 to remediate the vulnerability.

    0002097
    255 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Sysdig saw scans for PraisonAI auth bypass less than 4 hours after disclosure. CVE-2026-44338 impacts versions 2.5.6 to 4.6.33; fix is in 4.6.34. #PraisonAI #CVE-2026-44338 #Sysdig https://ift.tt/GfmtBwT

    Post summary

    Sysdig observed scans of the PraisonAI authentication bypass (CVE-2026-44338) within hours of disclosure, and a fix is available in version 4.6.34.

    00011134
    4.3K followersView on X
  • 西村/learningBOX/競プロアカ@ynishi2015
    Active Exploitation

    https://securityonline.info/praisonai-vulnerability-cve-2026-44338-exploited-in-the-wild/ セキュリティパッチがリリースされると、その差分を解析して数時間で攻撃が発生してしまうらしい。 セキュリティパッチをリリースしないわけにはいかない。厳しい世界だ。

    Post summary

    CVE‑2026‑44338 has been reported as being actively exploited in the wild, prompting an urgent security patch release.

    00020642
    26.1K followersView on X
  • 甲斐甲@k_aik_ou
    Disclosure

    📝 新着記事を公開しました 認証オフで公開されたPraisonAIのAPIサーバー、3時間44分でスキャンされた GitHubで★8.3k・フォーク1.3kを集めるマルチエージェントフレームワーク PraisonAI に、認証バイパスの脆弱性(CVE-2026-44338)が公開されました。GitHub Security Advisory が公開されてから… https://t.co/kTuGuk1tUV

    Post summary

    The tweet announces the disclosure of an authentication bypass vulnerability (CVE-2026-44338) in the PraisonAI API server, citing a GitHub Security Advisory.

    10000103
    638 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---

Explore more