Description
SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing agents belonging to a different organization without proper authorization checks. The endpoint accepts an agent_id parameter but does not verify that the agent belongs to the authenticated user's organization.
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Authorization Bypass
Action: Apply Update
AI Analysis

Impact

The vulnerability is present in the agent execution controller endpoint /api/agentexecutions/schedule of SuperAGI up to version 0.0.14. An authenticated caller can schedule an existing agent by supplying an agent_id. The code does not verify that the specified agent belongs to the caller’s organization, which allows a user from one organization to trigger an agent owned by another organization. This omission results in a classic authorization bypass flaw, corresponding to CWE‑285. The attacker can therefore execute arbitrary agents under another organization’s context, potentially exposing sensitive data or modifying downstream workloads.

Affected Systems

SuperAGI versions 0.0.14 and earlier are affected. The flaw specifically targets the /api/agentexecutions/schedule endpoint used by authenticated users. No additional vendors or product versions are listed in the advisory.

Risk and Exploitability

No CVSS or EPSS scores are available, but the issue permits a cross‑organization privilege escalation with only authenticated access. The flaw is not yet listed in CISA’s KEV catalog, indicating no known exploitation at this time. Nonetheless, the risk is high until an access‑control check is implemented or the product is updated.

Generated by OpenCVE AI on October 2, 2026 at 16:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SuperAGI to the most recent release (or any release that implements an ownership check for /api/agentexecutions/schedule).
  • Modify or extend the /api/agentexecutions/schedule handler to verify that the agent_id belongs to the authenticated user’s organization before scheduling the agent. This can be achieved by cross‑referencing the agent’s organization ID with the user’s organization.
  • If an immediate patch is not available, disable the scheduling endpoint for non‑administrative users or restrict it to administrators, effectively preventing cross‑organization scheduling until a fix is deployed.

Generated by OpenCVE AI on October 2, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Title Incorrect Access Control in SuperAGI Agent Execution Scheduling Endpoint
First Time appeared Transformeroptimus
Transformeroptimus superagi
Weaknesses CWE-285
Vendors & Products Transformeroptimus
Transformeroptimus superagi

Fri, 02 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing agents belonging to a different organization without proper authorization checks. The endpoint accepts an agent_id parameter but does not verify that the agent belongs to the authenticated user's organization.
References

Subscriptions

Transformeroptimus Superagi
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-02T15:34:43.780Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51901

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T16:16:49.980

Modified: 2026-10-02T16:16:49.980

Link: CVE-2026-51901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T16:30:14Z

Weaknesses