CVE-2026-47416
published 2026-07-21CVE-2026-47416: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation…
PriorityP260critical9.6CVSS 3.1
AVNACLPRLUINSCCHIHAN
EPSS
0.36%
27.6th percentile
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `require_workspace_member(workspace_id)`, which defaults to `min_role="member"` and is never overridden by the route. The handler then calls `MemberService.update_role(workspace_id, user_id, body.role)` which sets the target member's role to whatever the request body specifies, with no check that the caller has owner-or-admin privilege, no check that the new role is not higher than the caller's own, and no check that the caller is not silently promoting themselves. PraisonAI Platform version 0.1.4 patches the issue.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mervinpraison | praisonai-platform | < 0.1.4 | 0.1.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
praisonai-platform Workspace Member members privileges management
vuldb·2026-05-30
CVE-2026-47416 [CRITICAL] praisonai-platform Workspace Member members privileges management
A vulnerability, which was classified as critical, has been found in praisonai-platform. This vulnerability affects unknown code of the file /workspaces/{id}/members/ of the component Workspace Member Handler. The manipulation leads to improper privilege management.
This vulnerability is listed as CVE-2026-47416. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
GHSA
praisonai-platform: Any workspace member can promote themselves or others to owner via PATCH /workspaces/{id}/members/{user_id}
ghsa·2026-05-29
CVE-2026-47416 [CRITICAL] CWE-269 praisonai-platform: Any workspace member can promote themselves or others to owner via PATCH /workspaces/{id}/members/{user_id}
praisonai-platform: Any workspace member can promote themselves or others to owner via PATCH /workspaces/{id}/members/{user_id}
## Summary
**Type:** Vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `require_workspace_member(workspace_id)`, which defaults to `min_role="member"` and is never overridden by the route. The handler then calls `MemberService.update_role(workspace_id, user_id, body.role)` which sets the target member's role to whatever the request body specifies, with no check that the caller has owner-or-admin privilege, no check that the new role is not higher than the caller's own, and no check that the caller is not silently promoting themselves.
**File:** `src/praisonai-platform/praisonai_platform/api/routes/worksp
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-21
Published