External risk intelligence

PraisonAI Authentication Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-57147

The vulnerability exists in an authentication service for a multi-agent platform. Such platforms typically expose web APIs and user management interfaces to the internet or wide network segments to facilitate remote agent orchestration and collaboration, making the authentication endpoint a likely target for remote network exposure.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the PraisonAI multi-agent system allows remote attackers to impersonate users by forging security tokens. This is due to an issue with how authentication secrets are handled by default in certain configurations, potentially enabling unauthorized access to protected API routes. The primary concern is confirming whether this specific technology is in use and if it is exposed in a way that could be exploited.

  • Attackers can forge user identities.
  • Protects against unauthorized API access.
  • Confirm if this system is in use.

Attack Path

How an attacker could exploit the issue

An attacker can remotely forge authentication tokens to impersonate any user. This is possible because the system uses a predictable secret to sign tokens when a specific configuration is not set, and this setting bypasses a production check. An attacker could then use these forged tokens to access protected API routes as any user.

  • Unauthenticated network access required.
  • Predictable secret allows token forgery.
  • Unauthorized access to API routes.

Live Threat

Current exploitation, exposure, and threat context

A remote, unauthenticated attacker could forge authentication tokens, allowing them to impersonate any user on the PraisonAI platform. This could affect system access and user data by granting unauthorized individuals control over user accounts and their associated data.

  • User accounts and data.
  • Forged tokens bypass authentication.
  • Unauthorized access to sensitive information.

Operational Fix

Recommended remediation, mitigation, and detection steps

The PraisonAI platform's authentication service is vulnerable to remote unauthenticated attackers who can forge identities and access protected API routes. Application owners, in conjunction with platform and security teams, should first confirm the presence and reachability of the affected PraisonAI platform within their environment, identify the business criticality of exposed API routes, and then plan remediation.

  • Platform and application owners should take the lead.
  • Verify exposure of the authentication service.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PraisonAI and how does it function?

PraisonAI is a framework designed for building and managing multi-agent systems. It allows users to orchestrate autonomous AI agents that collaborate to complete complex tasks. The software includes a platform component responsible for managing these agent teams and providing API-based services for user authentication and coordination.

What is the vulnerability in CVE-2026-57147?

This vulnerability is classified as CWE-798 (Use of Hard-coded Credentials) and CWE-1188 (Insecure Default Initialization of Resource). It occurs because the system uses a publicly known, default value for its JWT signing secret when the proper production environment variables are not configured. This flaw allows an unauthorized person to create valid security tokens.

How does an attacker trigger this authentication bypass?

An attacker can trigger this by targeting the API when the environment is misconfigured to use the default secret. The vulnerability is active when the platform's security secret is not explicitly set and the environment defaults to development mode. It is not triggered if a secure, unique, and non-default secret is properly configured in the production environment.

Why should I care about this CVE if I run PraisonAI?

According to Halo Surface Signal, this software often exposes web APIs and user management interfaces to the internet to enable remote agent orchestration. Because this vulnerability allows unauthenticated access to protected API routes, any PraisonAI platform reachable from a broad network segment is at risk of being used to impersonate users.

How do I address the risk from CVE-2026-57147?

Your first step is to confirm if your environment runs an affected version of the PraisonAI platform. Identify the reachability of the authentication service and the sensitivity of the data handled by your agents. If you are running a version earlier than 0.1.6, prioritize upgrading your installation to the patched version as soon as possible.

References