In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_schedule, /api/agents/stop_schedule) allow authenticated users from one organization to create, schedule, edit, stop, and delete agents belonging to a different organization's project. The endpoints accept a project_id parameter but do not verify that the project belongs to the authenticated user's organization.

Project Subscriptions

Vendors Products
Transformeroptimus Subscribe
Superagi Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 02 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Title Cross‑Organization Agent Manipulation via Unchecked Project ID in SuperAGI
Weaknesses CWE-284

Fri, 02 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Transformeroptimus
Transformeroptimus superagi
Vendors & Products Transformeroptimus
Transformeroptimus superagi

Fri, 02 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_schedule, /api/agents/stop_schedule) allow authenticated users from one organization to create, schedule, edit, stop, and delete agents belonging to a different organization's project. The endpoints accept a project_id parameter but do not verify that the project belongs to the authenticated user's organization.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-02T15:34:01.979Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51899

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:49.867

Modified: 2026-10-02T17:59:09.430

Link: CVE-2026-51899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:00:17Z

Weaknesses