OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-51901

HIGH · CVSS 8.1 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability in SuperAGI up to version 0.0.14 allows authenticated users to schedule agents from other organizations due to inadequate access control on the agent execution controller endpoint. This could lead to unauthorized manipulation of agents, potentially compromising sensitive operations and data across organizations. Organizations using SuperAGI should prioritize addressing this issue to prevent unauthorized access and ensure proper isolation between user data.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51901
Severity
HIGH
CVSS
8.1
EPSS
0.25%

Original NVD Description

SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing agents belonging to a different organization without proper authorization checks. The endpoint accepts an agent_id parameter but does not verify that the agent belongs to the authenticated user's organization.