CVE-2026-51899
Received Received - Intake

Authenticated Agent Management in SuperAGI

Vulnerability report for CVE-2026-51899, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: MITRE

Description

In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_schedule, /api/agents/stop_schedule) allow authenticated users from one organization to create, schedule, edit, stop, and delete agents belonging to a different organization's project. The endpoints accept a project_id parameter but do not verify that the project belongs to the authenticated user's organization.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
superagi superagi 0.0.14
superagi superagi to 0.0.14 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-51899 is an improper access control vulnerability in SuperAGI v0.0.14 and earlier. Authenticated users can manipulate the project_id parameter in endpoints like /api/agents/create and /api/agents/delete to perform unauthorized actions on projects belonging to other organizations. The system fails to verify ownership of the project_id, allowing cross-organization agent management without proper authorization.

This vulnerability enables users to create, schedule, edit, stop, or delete agents in projects outside their organization by sending requests with a modified project_id parameter and their own authentication token. The system incorrectly processes these requests with HTTP 200 responses instead of rejecting them with 403 errors.

Detection Guidance

To detect this vulnerability, monitor HTTP requests to the affected endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_schedule, /api/agents/stop_schedule) for unauthorized project_id parameters. Check for HTTP 200 responses when actions are performed on projects not belonging to the authenticated user's organization.

Impact Analysis

This vulnerability allows attackers to gain unauthorized access to and control over agents in other organizations' projects. If exploited, it could lead to data breaches, unauthorized resource consumption, disruption of services, or manipulation of agent configurations across different organizations. The impact includes potential loss of data integrity, confidentiality, and availability for affected projects.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and access control in standards like GDPR and HIPAA. It undermines tenant isolation, allowing unauthorized access to sensitive data and systems across organizations. Organizations using SuperAGI may face compliance violations, regulatory penalties, and loss of trust due to inadequate access controls and potential data exposure.

Mitigation Strategies

Immediately update SuperAGI to the latest version beyond v0.0.14. Implement strict project_id validation to ensure it belongs to the authenticated user's organization. Restrict access to the affected endpoints and monitor for unusual cross-organization activities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-51899. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart