OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-51901 (CVSS 8.1)

NVD · officialPublished Oct 2, 2026Risk 37/100EPSS 0.2%

SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing agents belonging to a different organization without proper authorization checks. The endpoint accepts an agent_id parameter but does not verify that the agent belongs to the authenticated user's organization.

CVSS
8.1
AV:NetworkAC:LowPR:LowUI:NoneC:HighI:HighA:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source