MajorCritical vulnerability
CVE-2026-51914 (CVSS 8.8)
NVD · officialPublished Oct 2, 2026Risk 37/100EPSS 0.2%
TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_agent_as_template and publish_template in superagi/controllers/agent_template.py accept caller-supplied agent_id or agent_execution_id values and do not verify that the referenced agent or execution belongs to the authenticated user's organization.
Technical details
CVSS
8.8
AV:NetworkAC:LowPR:LowUI:NoneC:HighI:HighA:High
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source