UNKNOWN NVD
CVE-2026-51901
SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated user
SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing agents belonging to a different organization without proper authorization checks. The endpoint accepts an agent_id parameter but does not verify that the agent belongs to the authenticated user's organization.
References
- https://gist.github.com/Ro1ME/12fc58befd7fa2693bac98a91a4debf9
- https://github.com/TransformerOptimus/SuperAGI/issues/1557
This unknown severity vulnerability was published on 2026-10-02 via NVD.
vulnfeed aggregates 10027 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.