What happened
NVD published three unrated access-control CVEs for SuperAGI 0.0.14 on 2026-10-02 (CVE-2026-51901 scheduling, CVE-2026-51904 execution, CVE-2026-51914 templates): endpoints accept cross-organization agent references without ownership checks.
Why it matters
In a multi-tenant agent platform, cross-organization execution means a tenant can trigger another org's agents (which may carry that org's tool credentials and side effects) — an agentic-authz gap worth recording even at low urgency.
Attack vector
Caller-supplied agent_id / agent_execution_id values in /api/agentexecutions/schedule, create_agent_execution/create_agent_run, and agent-template endpoints are accepted without verifying the referenced agent belongs to the caller's organization.
Affected systems
SuperAGI <= 0.0.14
Mitigation
Apply upstream authorization fixes (verify ownership of agent_id in controllers) or restrict multi-tenant exposure pending patch.