Vulnerability  ·  2026-10-03

SuperAGI cross-tenant authorization bypass cluster: schedule/execute/run and template agents owned by other organizations (unrated)

VulnerabilityMedium impactGlobalCVE-2026-51904
NVD published a cluster of incorrect-access-control findings in SuperAGI 0.0.14 (CVE-2026-51901 scheduling, CVE-2026-51904 execution creation, CVE-2026-51914 template save/publish) where agent references are not validated against the caller's organization. Unrated/awaiting analysis as of publication.
In an open-source multi-tenant agent platform, a cross-tenant reference flaw lets one tenant's user drive another tenant's agents — a classic agent-framework authorization gap that can cross privilege boundaries and cause execution/infrastructure abuse between AI tenants.
Endpoints such as /api/agentexecutions/schedule and the create_agent_execution/create_agent_run handlers accept a caller-supplied agent_id or agent_execution_id without verifying the referenced agent belongs to the caller's organization, letting one tenant create/schedule/start execution records and publish templates for another tenant's agents.
TransformerOptimus SuperAGI up to 0.0.14 (agent_execution.py, agent_template.py controllers)
Monitor/apply upstream fix (SuperAGI issue #1557 area); restrict multi-tenant SuperAGI deployments to trusted users until patched.
NVD CVE-2026-51904NVD CVE-2026-51901NVD CVE-2026-51914
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →