S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jun 11, 2026

CVE-2026-44338 Scanner

CVE-2026-44338 Scanner - Broken Authentication vulnerability in PraisonAI

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-44338
7.3
CVSShigh
Exploitable remotely over the internet · no authentication required.

PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication disabled by default. When that server is used, any caller that can reach it can access /agents and trigger the configured agents.yaml workflow through /chat without providing a token. This issue has been patched in version 4.6.34.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
PraisonAIby MervinPraison
>= 2.5.6, < 4.6.34
Updated Aug 19, 2026View on NVD →
Detail

PraisonAI is a platform widely used in AI development environments, offering tools for machine learning, data processing, and workflow automation. It is frequently utilized by data scientists, AI engineers, and IT professionals in industries spanning from technology to finance. The platform integrates with various data sources and APIs to facilitate seamless AI model training and deployment. Users leverage PraisonAI for its robust capabilities in handling large datasets and complex algorithms. As a modular and scalable solution, it supports the quick development of AI projects by providing comprehensive resources and support. The tool's adaptability makes it an essential choice for enterprises focusing on innovative AI solutions.

The vulnerability identified in PraisonAI involves a broken authentication mechanism within its legacy Flask API server. This issue arises due to the default authentication being disabled, allowing unauthorized users to access specific API endpoints. Once exploited, attackers can potentially trigger agent workflows without requiring authentication. Such unauthorized actions create risk vectors where sensitive data might be exposed or manipulated. The flaw poses significant security concerns for organizations relying on PraisonAI for secure workflow operations. It underscores the critical nature of maintaining robust authentication controls in API services.

Technical details reveal that the vulnerable endpoint is `/agents`, accessible via the API's GET method without authentication. The vulnerability is exploitable when the server does not require a valid token for accessing this endpoint. Attackers can verify its susceptibility by checking for a successful HTTP 200 status code alongside specific response body contents like 'agent_file' and 'agents'. The issue originates from the systemic failure to enforce authentication measures, which should ideally restrict access based on verified credentials. This flaw can potentially be exploited remotely, requiring only network access to the vulnerable API server.

Exploitation of this vulnerability can lead to unauthorized access to critical operations and data managed by PraisonAI. An attacker could trigger workflow actions, access sensitive data, or disrupt normal service functions. Such activities may result in data breaches, loss of data integrity, or unintentional exposure of confidential information. These security implications can undermine the trust of stakeholders and compromise the integrity of the systems relying on PraisonAI. Addressing such vulnerabilities promptly is crucial to safeguarding the system against malicious exploits.

REFERENCES

Solution Advice
  • Upgrade PraisonAI to version 4.6.34 or later.
  • Implement strict authentication mechanisms for all API endpoints.
  • Regularly review and update security configurations for API services.
  • Conduct routine security audits and testing to identify potential flaws.
  • Ensure the use of strong and unique authentication tokens.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.