CVE-2026-61442
PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, an
CVSS
7.1
High
EPSS
0.3%
p17
KEV
—
Exploit Today
5
0-100
Published: Jul 11, 2026 · Last modified: Jul 13, 2026 · CWE-862
0.3%EPSS · 30 days0.3%
2026-07-122026-07-20
PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. A workspace member can modify owner-created records; for projects, a member can reassign lead_id to their own user id and then delete the owner-created project, bypassing the delete route's owner/admin permission check.
- github.comhttps://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753
- github.comhttps://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-c78w-2q4r-68r7
- www.vulncheck.comhttps://www.vulncheck.com/advisories/praisonai-platform-before-authorization-bypass-via-patch
- github.comhttps://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-c78w-2q4r-68r7
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-277718.2 HIG98.5%
——30Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.14dCVE-2023-361447.5 HIG98.3%
——30An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.12dCVE-2021-445958.8 HIG97.3%
——29Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the ElevationService.exe and execute arbitrary code without any validation with SYSTEM privileges.12dCVE-2020-253669.1 CRI82.1%
——25An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.12dCVE-2020-220076.8 MED81.0%
——24OS Command Injection vulnerability in OKER G955V1 v1.03.02.20161128, allows physical attackers to interrupt the boot sequence and execute arbitrary commands with root privileges.16dCVE-2026-405028.8 HIG74.5%
——22OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between local-only and remote-safe commands in the gateway handler. Attackers can execute administrative commands such as /permissions full_auto through remote chat sessions to change permission modes of a running OpenHarness instance without operator authorization.6d