CVE-2026-51914
Received Received - Intake

Incorrect Access Control in TransformerOptimus SuperAGI

Vulnerability report for CVE-2026-51914, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: MITRE

Description

TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_agent_as_template and publish_template in superagi/controllers/agent_template.py accept caller-supplied agent_id or agent_execution_id values and do not verify that the referenced agent or execution belongs to the authenticated user's organization.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

TransformerOptimus SuperAGI v0.0.14 has an Incorrect Access Control vulnerability in the agent template controller. The functions save_agent_as_template and publish_template in superagi/controllers/agent_template.py do not verify if the agent_id or agent_execution_id belongs to the authenticated user's organization. This allows unauthorized access to templates from other organizations.

Impact Analysis

An attacker could exploit this to access or publish agent templates from other organizations without authorization. This may lead to data leaks, unauthorized modifications, or misuse of agent templates across organizational boundaries.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized access to sensitive data or agent templates. It may lead to breaches of confidentiality, integrity, or availability, which are critical under GDPR and HIPAA.

Mitigation Strategies

Immediately update SuperAGI to a patched version beyond v0.0.14. Review agent_template.py for the save_agent_as_template and publish_template functions to ensure proper verification of agent_id and agent_execution_id ownership. Restrict access to these functions to authenticated users within their organizations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-51914. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart