Vulnerability Description
TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_agent_as_template and publish_template in superagi/controllers/agent_template.py accept caller-supplied agent_id or agent_execution_id values and do not verify that the referenced agent or execution belongs to the authenticated user's organization.
References
FAQ
What is CVE-2026-51914?
CVE-2026-51914 is a documented vulnerability. TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_agent_as_template and publish_template in superagi/co...
How severe is CVE-2026-51914?
CVSS scoring is not yet available for CVE-2026-51914. Check NVD for updates.
Is there a patch for CVE-2026-51914?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.