Impact
SuperPlane before version 0.27.0 contains a broken object‑level authorization flaw in the CanvasService gRPC handlers. An authenticated user with only viewer‑level access to one organization can supply arbitrary canvas or queue UUIDs that are not scoped to an organization, thereby bypassing authorization checks. This allows the attacker to read execution history and event payloads of other organizations, write queue items and canvas events into victim organizations, delete arbitrary canvases, and disrupt automation workflows across tenant boundaries.
Affected Systems
The affected product is SuperPlane from SuperPlaneHQ. All releases prior to 0.27.0 are vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7, indicating high severity. The EPSS score is below 1 %, suggesting a low probability of exploitation at present. It is not listed in CISA’s KEV catalog. Attackers would need to be authenticated via gRPC and possess viewer‑level credentials; under those conditions, the flaw permits cross‑tenant data access and modification.
OpenCVE Enrichment