A vulnerability classified as problematic has been found in MervinPraison praisonai-platform up to 0.1.3. Affected is the function
MemberService.add of the component MemberService. This manipulation of the argument user_id/role causes improper privilege management.
This vulnerability is registered as CVE-2026-47413. Remote exploitation of the attack is possible. No exploit is available.