THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-48169 (HIGH 8.8) — PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups without checking workspace ownersh

[NVD] CVE-2026-48169 (HIGH 8.8) — PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups without checking workspace ownersh

lownvdPublished 2026-08-07

CVE-2026-48169 CVSS: 8.8 HIGH Published: 2026-08-07T22:16:59.013

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups without checking workspace ownership, so any authenticated user can read, modify, and de

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-48169