CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-47416

criticalCVSS 9.6covered by 1 sourcefirst seen 2026-07-21
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The PATCH /workspaces/{workspace_id}/members/{user_id} endpoint is gated by require_workspace_member(workspace_id), which defaults to min_role="member" and is never overridden by the route. The handler then calls MemberService.update_role(workspace_id, user_id, body.role) which sets the target member's role to whatever the request body specifies, with no check that the caller has owner-or-admin privilege, no check that the new role is not higher than the caller's own, and no check that the caller is not silently promoting themselves. PraisonAI Platform version 0.1.4 patches the issue.

⚡ Watch CVE-2026-47416

Get an email if CVE-2026-47416 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-47416

CVE.org record

Embed the live status

CVE-2026-47416 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-47416 status](https://www.csirts.com/badge/CVE-2026-47416)](https://www.csirts.com/cve/CVE-2026-47416)