External risk intelligence

SuperAGI Improper Access Control Vulnerability in Agent Execution Controller.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51904

SuperAGI is an agent orchestration platform typically deployed as a web application or API service to facilitate user interactions with agents. Because these services are commonly hosted as internet-facing web endpoints to allow remote access and collaboration, the agent execution controller functions are frequently reachable via the public internet in standard deployment patterns.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in the agent execution controller for SuperAGI allows authenticated users to access or control agents belonging to other organizations. This could potentially lead to unauthorized actions or data exposure if not properly managed.

  • Unauthorized access to another organization's agents.
  • Matters due to potential for data misuse or disruption.
  • Confirm relevance and exposure to your deployed agents.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated access to one organization could manipulate the agent execution controller to create or run agents belonging to a different organization. This is possible because the system fails to properly verify ownership of agent IDs when new execution records are requested. Successful exploitation allows an attacker to impact agent operations in another organization.

  • Authenticated access to the system is required.
  • Caller-supplied agent IDs are not validated.
  • Unauthorized agent execution and control.

Live Threat

Current exploitation, exposure, and threat context

A remote attacker with authentication could abuse improper access control to create or start agent execution records for agents belonging to different organizations. This could affect the integrity and availability of agent execution data within the affected system.

  • Agent execution data at risk.
  • Unauthorized agent execution creation.
  • Compromised agent operational integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts SuperAGI's agent execution controller, allowing authenticated remote attackers to manipulate agents across different organizations. The primary responsibility for addressing this typically falls to the platform or application owners who manage SuperAGI deployments, in coordination with security teams to understand exposure. The first practical step is to identify all SuperAGI instances, determine their reachability and business criticality, and confirm ownership before planning remediation.

  • Platform owners must identify all instances.
  • Verify agent data access and cross-organization exposure.
  • Coordinate remediation with affected application owners.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is SuperAGI?

SuperAGI is an open-source agent orchestration platform. It provides a framework for developers and organizations to build, deploy, and manage autonomous AI agents that perform tasks, interact with data, and execute workflows through a centralized controller interface.

What is the vulnerability in CVE-2026-51904?

This vulnerability is an improper access control issue, categorized under CWE-284. It means the software does not correctly restrict what a user is allowed to do. Specifically, the system fails to check if an agent belongs to the user's own organization before allowing them to trigger actions on it.

How does an attacker trigger this bug?

An attacker needs an authenticated account within the platform to trigger this. By supplying an agent ID belonging to a different organization during an execution request, they bypass authorization checks. Note that this flaw does not involve guessing passwords; it requires the ability to successfully authenticate as a user on the platform first.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal notes that SuperAGI is frequently deployed as an internet-facing web application to support remote collaboration. Because these endpoints are commonly reachable via the public internet, they are highly accessible to remote authenticated attackers, increasing the relevance of this flaw for most standard deployments.

What should I do if I run SuperAGI?

Begin by creating an inventory of all your SuperAGI instances to understand where they are deployed. Evaluate the network reachability of these instances and verify if your current configurations allow users to access cross-organizational agent data. Coordinate with your application owners to prioritize these systems for remediation.

References