What happened
NVD published a cluster of incorrect-access-control findings in SuperAGI 0.0.14 (CVE-2026-51901 scheduling, CVE-2026-51904 execution creation, CVE-2026-51914 template save/publish) where agent references are not validated against the caller's organization. Unrated/awaiting analysis as of publication.
Why it matters
In an open-source multi-tenant agent platform, a cross-tenant reference flaw lets one tenant's user drive another tenant's agents — a classic agent-framework authorization gap that can cross privilege boundaries and cause execution/infrastructure abuse between AI tenants.
Attack vector
Endpoints such as /api/agentexecutions/schedule and the create_agent_execution/create_agent_run handlers accept a caller-supplied agent_id or agent_execution_id without verifying the referenced agent belongs to the caller's organization, letting one tenant create/schedule/start execution records and publish templates for another tenant's agents.
Affected systems
TransformerOptimus SuperAGI up to 0.0.14 (agent_execution.py, agent_template.py controllers)
Mitigation
Monitor/apply upstream fix (SuperAGI issue #1557 area); restrict multi-tenant SuperAGI deployments to trusted users until patched.