PT-2026-65575 · Unknown · Superplane

·

CVE-2026-57510

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SuperPlane versions prior to 0.27.0
Description An issue exists in the CanvasService gRPC handlers where broken object-level authorization allows authenticated users with viewer-level access in one organization to access resources of other organizations. This occurs when arbitrary canvas or queue UUIDs are supplied without organization scoping. This flaw enables attackers to read cross-tenant execution history and event payloads containing sensitive secrets, write queue items and canvas events into victim organizations, delete arbitrary canvases, and disrupt automation workflows across tenant boundaries.
Recommendations Update SuperPlane to version 0.27.0 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57510

Affected Products

Superplane