CVE-2026-57510
Received Received - Intake

Broken Object-Level Authorization in SuperPlane

Vulnerability report for CVE-2026-57510, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: VulnCheck

Description

SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to access resources belonging to other organizations by supplying arbitrary canvas or queue UUIDs without organization scoping. Attackers can read cross-tenant execution history and event payloads containing sensitive secrets, write queue items and canvas events into victim organizations, delete arbitrary canvases, and disrupt automation workflows across tenant boundaries.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-29
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
superplanehq superplane to 0.27.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a broken object-level authorization flaw in SuperPlane before version 0.27.0. It exists in the CanvasService gRPC handlers and allows authenticated users with viewer-level access to one organization to access resources belonging to other organizations by supplying arbitrary canvas or queue UUIDs without proper organization scoping.

Detection Guidance

To detect this vulnerability, check if your SuperPlane instance is running a version before 0.27.0. Verify the gRPC CanvasService handlers for improper organization scoping in canvas or queue UUID handling. Monitor for unauthorized cross-tenant access attempts or unusual activity in execution history and event payloads.

Impact Analysis

Attackers can exploit this to read sensitive secrets from cross-tenant execution history and event payloads, write queue items and canvas events into victim organizations, delete arbitrary canvases, and disrupt automation workflows across tenant boundaries.

Compliance Impact

This vulnerability allows unauthorized cross-tenant access to sensitive data, including execution history and secrets. This could violate GDPR's data protection requirements (Article 32) and HIPAA's safeguards for protected health information by enabling unauthorized access to sensitive data across organizations.

Mitigation Strategies

Upgrade SuperPlane to version 0.27.0 or later to patch the vulnerability. Review and restrict user permissions to ensure least privilege access. Monitor network traffic for unauthorized gRPC requests to CanvasService handlers. Audit cross-tenant data access logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57510. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart