CVE-2026-51904: n/a
SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent_execution and create_agent_run in superagi/controllers/agent_execution.py accept a caller-supplied agent_id and fail to verify that the referenced agent belongs to the authenticated user's organization. A remote authenticated attacker from one organization can create or start execution records for agents owned by another organization through /agentexecutions/add or /agentexecutions/add_run.
AI Analysis
Technical Summary
CVE-2026-51904 describes an improper access control vulnerability in SuperAGI up to version 0.0.14. The vulnerability exists in the agent execution controller, specifically in the create_agent_execution and create_agent_run functions within superagi/controllers/agent_execution.py. These functions accept a caller-supplied agent_id but fail to verify ownership of the agent relative to the authenticated user's organization. Consequently, an authenticated attacker can create or start execution records for agents belonging to other organizations by accessing the endpoints /agentexecutions/add or /agentexecutions/add_run.
Potential Impact
An authenticated attacker from one organization can manipulate agent execution records of agents owned by other organizations. This could lead to unauthorized creation or initiation of agent executions across organizational boundaries, potentially causing data integrity issues or unauthorized actions within the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the affected endpoints to trusted users only and monitor for suspicious activity related to agent execution creation and runs. Implement additional access control checks to verify agent ownership before allowing execution creation or start.
CVE-2026-51904: n/a
Description
SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent_execution and create_agent_run in superagi/controllers/agent_execution.py accept a caller-supplied agent_id and fail to verify that the referenced agent belongs to the authenticated user's organization. A remote authenticated attacker from one organization can create or start execution records for agents owned by another organization through /agentexecutions/add or /agentexecutions/add_run.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-51904 describes an improper access control vulnerability in SuperAGI up to version 0.0.14. The vulnerability exists in the agent execution controller, specifically in the create_agent_execution and create_agent_run functions within superagi/controllers/agent_execution.py. These functions accept a caller-supplied agent_id but fail to verify ownership of the agent relative to the authenticated user's organization. Consequently, an authenticated attacker can create or start execution records for agents belonging to other organizations by accessing the endpoints /agentexecutions/add or /agentexecutions/add_run.
Potential Impact
An authenticated attacker from one organization can manipulate agent execution records of agents owned by other organizations. This could lead to unauthorized creation or initiation of agent executions across organizational boundaries, potentially causing data integrity issues or unauthorized actions within the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the affected endpoints to trusted users only and monitor for suspicious activity related to agent execution creation and runs. Implement additional access control checks to verify agent ownership before allowing execution creation or start.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-06-08T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 6abfd1dda43b0b3b89d26ab1
Added to database: 10/02/2026, 15:46:37 UTC
Last enriched: 10/02/2026, 16:01:07 UTC
Last updated: 10/03/2026, 03:04:40 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.