Description
TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without requiring authentication in the route and without verifying organization ownership of the supplied knowledge_id.
Published: 2026-10-02
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized deletion of knowledge objects
Action: Patch Immediately
AI Analysis

Impact

TransformerOptimus SuperAGI v0.0.14 contains an improper access control flaw that allows an attacker to delete knowledge entries without providing any authentication and without verifying that the requester owns the organization responsible for the knowledge. This vulnerability could enable a malicious user to remove or corrupt data that is central to the AI model’s performance, potentially causing loss of critical business information or compromising downstream services that rely on the knowledge base.

Affected Systems

The flaw is present in the SuperAGI v0.0.14 source, specifically within superagi/controllers/knowledges.py which handles the POST /knowledges/delete/{knowledge_id} route. Systems running this exact version or earlier source snapshots are vulnerable; later versions that implement proper authentication or ownership verification are not affected.

Risk and Exploitability

The vulnerability requires the attacker to send an HTTP POST request to the delete endpoint. Because no authentication is required, an attacker only needs network access to the host exposing the API. There is no known public exploit, and no EPSS data is available, but the lack of authentication means the risk of exploitation is high if the endpoint is reachable. The vulnerability is not listed in CISA KEV, but its impact remains significant.

Generated by OpenCVE AI on October 2, 2026 at 17:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a patched or newer release of TransformerOptimus SuperAGI that enforces authentication and verifies organization ownership when deleting knowledge objects.
  • If a patch is not immediately available, restrict access to the /knowledges/delete/* endpoint with network controls such as firewall rules or reverse‑proxy authentication to limit exposure to trusted users.
  • Regularly audit API logs for unexpected POST requests to the delete endpoint and review any knowledge deletions for unauthorized activity.

Generated by OpenCVE AI on October 2, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Transformeroptimus
Transformeroptimus superagi
Vendors & Products Transformeroptimus
Transformeroptimus superagi

Fri, 02 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control Enables Unauthenticated Deletion of Knowledge in SuperAGI
Weaknesses CWE-284

Fri, 02 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without requiring authentication in the route and without verifying organization ownership of the supplied knowledge_id.
References

Subscriptions

Transformeroptimus Superagi
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-02T20:20:04.497Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51916

cve-icon Vulnrichment

Updated: 2026-10-02T20:18:56.783Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:50.763

Modified: 2026-10-02T21:16:55.427

Link: CVE-2026-51916

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T19:15:18Z

Weaknesses