Product
high
advisory
praisonai-platform: Cross-Workspace Label IDOR Vulnerability
2 rules 3 TTPsPraison AI's praisonai-platform is vulnerable to an insecure direct object reference (IDOR) in the label endpoints (CVE-2026-47414), allowing cross-workspace label modification and information disclosure due to improper validation of label and issue IDs.
praisonai-platform
idor
vulnerability
privilege-escalation
collection
impact
cloud
2r
3t
critical
threat
PraisonAI Platform Workspace Cross-Access Vulnerability
2 rules 1 TTPPraisonAI Platform's workspace-scoped REST routes have an object-level authorization flaw allowing authenticated users from one workspace to access, modify, and delete objects in another workspace by providing the victim object's global UUID.
PraisonAI Platform
authorization
privilege-escalation
workspace-bypass
2r
1t