OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-51904

CRITICAL · CVSS 9.8 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

SuperAGI versions up to v0.0.14 have an improper access control vulnerability in the agent execution controller, allowing remote authenticated attackers to manipulate agent execution records across different organizations. This flaw enables attackers to create or initiate execution records for agents that do not belong to their organization, potentially leading to unauthorized access and data manipulation. Organizations using SuperAGI should prioritize remediation to prevent exploitation of this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51904
Severity
CRITICAL
CVSS
9.8
EPSS
0.19%

Original NVD Description

SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent_execution and create_agent_run in superagi/controllers/agent_execution.py accept a caller-supplied agent_id and fail to verify that the referenced agent belongs to the authenticated user's organization. A remote authenticated attacker from one organization can create or start execution records for agents owned by another organization through /agentexecutions/add or /agentexecutions/add_run.