CVE-2026-47396: PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset
PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN` is not configured. The affected component is the `praisonai.api.agent_invoke` router as mounted by `praisonai.api.call`. The authentication helper `verify_token()` fails open when `CALL_SERVER_TOKEN` is unset. Since every sensitive agent-control endpoint depends on this helper, starting the call server without a token allows any reachable client to list agents, inspect agent metadata and instructions, invoke agents, and unregister agents. This is security-relevant because the bundled call server includes the vulnerable router and binds to `0.0.0.0`. As a result, operators who launch the call server without explicitly setting `CALL_SERVER_TOKEN` may unintentionally expose an unauthenticated remote agent control plane. Version 4.6.40 fixes the issue.
Security readout for executives and security teams
Plain-English summary
PraisonAI call servers started without CALL_SERVER_TOKEN may expose an unauthenticated remote control plane. A reachable attacker could see agent details, trigger agents, or remove registered agents. The issue is fixed in version 4.6.40.
Executive priority
Treat this as urgent for any exposed PraisonAI call server. Prioritize upgrade and token enforcement because the flaw affects confidentiality, integrity, and availability of agent operations.
Technical view
Before 4.6.40, praisonai.api.call mounts the agent_invoke router, whose sensitive endpoints depend on verify_token(). That helper fails open when CALL_SERVER_TOKEN is unset. Because the bundled call server binds to 0.0.0.0, reachable clients can access agent listing, metadata inspection, invocation, and unregistration without authentication.
Likely exposure
Highest risk is PraisonAI versions earlier than 4.6.40 running the call server without CALL_SERVER_TOKEN, especially if reachable from untrusted networks or the internet.
Exploitation context
The bundle does not cite active exploitation, and KEV is false. Risk is still high because exploitation requires network reachability and no credentials when the token is unset.
Researcher notes
The root issue is fail-open authentication in verify_token() when CALL_SERVER_TOKEN is unset. The vulnerable router is agent_invoke as mounted by praisonai.api.call. Sources identify CWE-284 and CWE-306 with CVSS 3.1 score 9.8.
Mitigation direction
Upgrade PraisonAI to version 4.6.40 or later.
Set CALL_SERVER_TOKEN for any call server deployment.
Restrict call server network exposure to trusted hosts or private networks.
Disable the call server where it is not operationally required.
Review vendor guidance for any additional hardening steps.
Validation and detection
Inventory PraisonAI deployments and identify versions earlier than 4.6.40.
Confirm whether the call server is running in each deployment.
Verify CALL_SERVER_TOKEN is explicitly configured where the call server is used.
Check whether the service is reachable from untrusted networks.
Review logs for unexpected agent listing, invocation, or unregistration activity.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-284: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Authentication and credential weaknesses can make valid-account abuse and credential telemetry useful review starting points. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
3Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: yesTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.