PT-2026-104364 · Undefined · Undefined
CVE-2026-51901
·
Published
2026-10-02
·
Updated
2026-10-02
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing agents belonging to a different organization without proper authorization checks. The endpoint accepts an agent id parameter but does not verify that the agent belongs to the authenticated user's organization.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined