External risk intelligence

PraisonAI Authentication Bypass Allows Impersonation

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-57148

The vulnerability exists in an authentication service for a multi-agent platform. Such platforms are typically deployed as web applications or API services intended for user interaction, making them commonly reachable as internet-facing services.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts PraisonAI, a multi-agent system, by allowing unauthenticated attackers to impersonate users or workspace owners through a flaw in its authentication service. The issue stems from an insecure default secret key used for signing security tokens, which can be exploited when specific configuration settings are not met. This could potentially lead to unauthorized access and control over system resources and user data.

  • Authentication weakness allows impersonation.
  • Affects PraisonAI multi-agent systems.
  • Confirm if PraisonAI is in use.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by sending a specially crafted JSON Web Token (JWT) that bypasses authentication checks. This is possible because the system defaults to a predictable signing key and disables crucial security guards in its development environment. If successful, the attacker could impersonate a legitimate user or workspace owner, leading to unauthorized access and control.

  • Unauthenticated network access required.
  • Malicious JWT bypasses authentication.
  • Impersonation and unauthorized access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to impersonate a user or workspace owner by signing a malicious JSON Web Token (JWT) when the system is configured with default development secrets and environments. This impersonation could occur when a target user or workspace identifier is known to the attacker.

  • User or workspace identity.
  • Unauthenticated token signing.
  • Unauthorized access to resources.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in PraisonAI's authentication service, which allows for unauthenticated user impersonation, likely impacts platform or application owners responsible for the PraisonAI deployment. The first practical step is to confirm the presence and reachability of the affected PraisonAI platform, identify the accountable system owner, and then assess the business criticality to prioritize remediation efforts.

  • Platform/Application owners should own.
  • Verify deployment reachability and criticality.
  • Plan vendor coordination and update.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PraisonAI?

PraisonAI is a framework used to build and manage multi-agent teams, which are systems where multiple artificial intelligence agents collaborate to perform tasks. Developers and organizations use this software to orchestrate complex AI workflows, often requiring a platform or web service component to handle user authentication, workspace management, and agent coordination.

How does CVE-2026-57148 create an authentication weakness?

This vulnerability is primarily a failure in authentication (CWE-287) caused by the use of hardcoded credentials (CWE-798). Specifically, if the platform is not configured with a custom secret, it defaults to a public, known signing key for its JSON Web Tokens. Because the system also defaults to a development environment state that disables security guards, an attacker can generate their own valid-looking tokens to impersonate any user or workspace owner.

Does any activity trigger this vulnerability?

This flaw is triggered only when the system is running with default configuration settings where the environment is set to development and the platform secret is unset. Simply having the software installed does not trigger the bug; the vulnerability remains inactive if administrators properly configure their environment variables to use unique, private secrets and production security settings.

Is my PraisonAI instance at risk?

You should consider your instance at risk if it is internet-facing, as Halo Surface Signal identifies these types of multi-agent platforms as commonly reachable via public networks. Because the exploit involves sending a crafted token over the network, any PraisonAI deployment that accepts external connections is a potential target for unauthorized impersonation attempts.

What is the first step to address this CVE?

The immediate priority is to verify if you are running a version of the PraisonAI platform prior to 0.1.6. If so, your primary action is to update the software to version 0.1.6 or later, which contains the necessary security fixes. Simultaneously, consult your deployment configuration to ensure that all environment variables, especially those related to JWT secrets, are explicitly set to secure, unique values rather than defaults.

References