Description
SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to access resources belonging to other organizations by supplying arbitrary canvas or queue UUIDs without organization scoping. Attackers can read cross-tenant execution history and event payloads containing sensitive secrets, write queue items and canvas events into victim organizations, delete arbitrary canvases, and disrupt automation workflows across tenant boundaries.
Published: 2026-07-28
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SuperPlane before version 0.27.0 contains a broken object‑level authorization flaw in the CanvasService gRPC handlers. An authenticated user with only viewer‑level access to one organization can supply arbitrary canvas or queue UUIDs that are not scoped to an organization, thereby bypassing authorization checks. This allows the attacker to read execution history and event payloads of other organizations, write queue items and canvas events into victim organizations, delete arbitrary canvases, and disrupt automation workflows across tenant boundaries.

Affected Systems

The affected product is SuperPlane from SuperPlaneHQ. All releases prior to 0.27.0 are vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 8.7, indicating high severity. The EPSS score is below 1 %, suggesting a low probability of exploitation at present. It is not listed in CISA’s KEV catalog. Attackers would need to be authenticated via gRPC and possess viewer‑level credentials; under those conditions, the flaw permits cross‑tenant data access and modification.

Generated by OpenCVE AI on August 3, 2026 at 14:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SuperPlane to version 0.27.0 or later to apply the fix that enforces organization scoping in CanvasService gRPC calls
  • Revoke or tightly limit viewer‑level permissions for organizations that have not yet been upgraded to avoid the potential for cross‑tenant access
  • Monitor system logs for unexpected canvas or queue actions originating from users who should not have cross‑tenant access; investigate any anomalies promptly

Generated by OpenCVE AI on August 3, 2026 at 14:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Superplanehq
Superplanehq superplane
Vendors & Products Superplanehq
Superplanehq superplane

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Description SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to access resources belonging to other organizations by supplying arbitrary canvas or queue UUIDs without organization scoping. Attackers can read cross-tenant execution history and event payloads containing sensitive secrets, write queue items and canvas events into victim organizations, delete arbitrary canvases, and disrupt automation workflows across tenant boundaries.
Title SuperPlane < 0.27.0 Broken Object Level Authorization via CanvasService gRPC
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Superplanehq Superplane
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T19:50:02.065Z

Reserved: 2026-06-24T15:58:58.536Z

Link: CVE-2026-57510

cve-icon Vulnrichment

Updated: 2026-07-28T19:49:32.663Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T20:17:27.027

Modified: 2026-07-30T16:41:25.650

Link: CVE-2026-57510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:30:18Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key