Threats Tagged 'cve-2026-48169'
View all threats tagged with 'cve-2026-48169'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-48169'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-48169: CWE-639: Authorization Bypass Through User-Controlled Key in MervinPraison praisonai-platformCVE-2026-48169 0 CVE-2026-48169 affects the PraisonAI Platform API versions prior to 0.1.4 and involves authorization bypass vulnerabilities that break workspace isolation. The service layer performs global primary-key lookups without verifying workspace ownership, allowing authenticated users to access resources across workspaces by manipulating UUIDs. Additionally, member management endpoints require only minimal role checks, enabling members to escalate their privileges to owner and remove original owners. These combined flaws allow low-privilege members to steal data and take over any workspace they belong to. Version 0.1.4 of the PraisonAI Platform API addresses these issues. Join the discussion | CVE Database V5 | 08/07/2026, 21:22:04 UTC Added: 08/07/2026, 21:42:04 UTC |
Showing 1 to 1 of 1 result