Security researchers disclosed CVE-2026-44338, a missing-authentication vulnerability (CVSS 7.3) in PraisonAI, an open-source multi-agent orchestration framework, affecting versions 2.5.6 through 4.6.33. The framework’s legacy Flask API server shipped with authentication disabled by default, letting any caller reach its /agents and /chat endpoints and trigger configured agent workflows without a token. Scanners began probing the vulnerable endpoint within roughly four hours of the May 11, 2026 public advisory. The issue is fixed in version 4.6.34, which requires an explicit API key.