Vulnary
← back to the feed
Critical· 9.4official fix available

CVE-2026-47407

PraisonAI Platform versions before 0.1.4 allow users to access and modify resources belonging to other workspaces, and to promote themselves to higher roles. The flaw arises because the API does not verify that the resource’s workspace matches the URL prefix, and role checks are not enforced. Upgrading to 0.1.4 or later fixes the issue.

publishedJul 21, 2026
last modifiedJul 22, 2026
sourcesNVD
severity · cvss
9.4
critical · how bad it is
exploitation · epss
<1%
15th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 20, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Users of PraisonAI Platform running any version earlier than 0.1.4, including administrators and members of workspaces that can register new accounts without email verification.

02

Real-world impact

An attacker who is a member of one workspace can read, update, or delete data from any other workspace, and can promote themselves to admin or owner, potentially compromising all data and control within the platform.

03

Why this severity

The CVSS score of 9.4 reflects the combination of high confidentiality, integrity, and availability impact, along with the ability to elevate privileges and bypass authentication checks. The vulnerability allows an attacker to gain full control over other workspaces and the entire platform, justifying the critical rating.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade PraisonAI Platform to version 0.1.4 or later.
  2. 02Verify that the new version is running by checking the platform’s version endpoint or release notes.
  3. 03Restart the platform service to ensure the updated code is active.

NVD-referenced vendor advisory

05

Timeline

  1. Jul 21, 2026 · 11d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 21, 2026 · 11d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredLow
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2026-47407: PraisonAI Platform versions before 0.1.4 allow users to access and mod · Vulnary