CVE-2026-61439
PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity
CVSS
7.5
Alto
EPSS
0.3%
p18
KEV
—
Exploit Today
5
0-100
Publicado: 11 jul 2026 · Última mod.: 14 jul 2026 · CWE-1188
0.3%EPSS · 30 días0.3%
2026-07-122026-07-20
PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that trigger HIGH severity detection but are logged without blocking, enabling system prompt extraction and unauthorized tool invocations.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-62415——
———The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.5hCVE-2026-600249.8 CRÍ4.3%
——1The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.19hCVE-2026-621857.6 ALT20.5%
——6Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this unrestricted network access through combined attacks to achieve cluster compromise and remote code execution.6dCVE-2026-548004.8 MED4.2%
——1A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.12dCVE-2026-144748.8 ALT27.1%
——8A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.15hCVE-2026-562858.6 ALT28.4%
——9Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the server, including cloud metadata services and internal network resources.7d