PT-2026-104363 · Undefined · Undefined

CVE-2026-51899

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit schedule, /api/agents/stop schedule) allow authenticated users from one organization to create, schedule, edit, stop, and delete agents belonging to a different organization's project. The endpoints accept a project id parameter but do not verify that the project belongs to the authenticated user's organization.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-51899

Affected Products

Undefined