Vulnerability  ·  2026-10-03

SuperAGI cross-organization agent-execution access control: schedule/run agents belonging to other orgs (CVE-2026-51901/51904/51914)

VulnerabilityMedium impactGlobalCVE-2026-51901
NVD published three unrated access-control CVEs for SuperAGI 0.0.14 on 2026-10-02 (CVE-2026-51901 scheduling, CVE-2026-51904 execution, CVE-2026-51914 templates): endpoints accept cross-organization agent references without ownership checks.
In a multi-tenant agent platform, cross-organization execution means a tenant can trigger another org's agents (which may carry that org's tool credentials and side effects) — an agentic-authz gap worth recording even at low urgency.
Caller-supplied agent_id / agent_execution_id values in /api/agentexecutions/schedule, create_agent_execution/create_agent_run, and agent-template endpoints are accepted without verifying the referenced agent belongs to the caller's organization.
SuperAGI <= 0.0.14
Apply upstream authorization fixes (verify ownership of agent_id in controllers) or restrict multi-tenant exposure pending patch.
NVD CVE-2026-51901NVD CVE-2026-51904Ro1ME gist — SuperAGI cross-org schedulingNVD CVE-2026-51914
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →