CVE-2026-47416
PraisonAI Platform versions earlier than 0.1.4 allow any workspace member to change another member’s role through a PATCH endpoint without proper checks. This flaw lets a user elevate privileges or promote themselves to higher roles. The issue is fixed in version 0.1.4.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Organizations using PraisonAI Platform for multi‑agent teams, specifically those running versions prior to 0.1.4.
Real-world impact
An attacker who is a member of a workspace could change the role of any other member or themselves to an owner or admin level, giving them full control over the workspace and its data.
Why this severity
The CVSS score of 9.6 reflects that the vulnerability can be exploited over the network with low effort, requires only low privileges, and has no user interaction. It changes the scope of the system and provides high confidentiality and integrity impact, making it a critical flaw.
What to do about it
- 011. Verify the current PraisonAI Platform version.
- 022. Upgrade the platform to version 0.1.4 or later.
- 033. Restart the PraisonAI Platform service if required.
NVD-referenced vendor advisory
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.