External risk intelligence

TransformerOptimus SuperAGI Improper Access Control Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51915

The vulnerability exists in the tool controller of an agentic application, which functions as an API service. These types of web-based APIs are commonly deployed as internet-facing services to allow remote access and integration, making them frequently exposed in standard production environments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in the tool controller component of TransformerOptimus SuperAGI, a technology used for agentic applications. This issue allows authenticated users from one organization to potentially access or alter tool data belonging to other organizations. The main concern is confirming if this specific technology is in use and, if so, assessing the potential exposure.

  • Unauthorized access to organizational tools.
  • Matters if agentic applications manage sensitive tool data.
  • Confirm usage and assess relevance to business operations.

Attack Path

How an attacker could exploit the issue

An attacker could begin by gaining authenticated access to the application, then using this access to target another organization's tool information. The vulnerability lies in how the tool controller handles requests for tool data, specifically by not checking if the authenticated user belongs to the same organization as the requested tool. This allows unauthorized access to sensitive tool metadata.

  • Requires authenticated access.
  • Triggered by requesting another organization's tool.
  • Risk: unauthorized data access and modification.

Live Threat

Current exploitation, exposure, and threat context

A remote attacker could access or alter tool metadata belonging to other organizations when supported by the advisory. This could occur if an attacker, authenticated within one organization, targets the tool controller's API endpoints with tool IDs from a different organization.

  • Tool metadata could be exposed.
  • Unauthorized tool access or modification.
  • Compromised agent functionality.

Operational Fix

Recommended remediation, mitigation, and detection steps

TransformerOptimus SuperAGI's tool controller contains a critical access control vulnerability, allowing authenticated attackers to access or modify tool metadata across different organizations. This necessitates immediate identification of affected deployments, confirmation of business criticality and network reachability, and accountability assignment before planning remediation.

  • Assign ownership to SuperAGI application owners.
  • Verify tool controller's network exposure and criticality.
  • Plan remediation based on identified risk exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is TransformerOptimus SuperAGI?

TransformerOptimus SuperAGI is a software framework designed for building agentic applications. These applications leverage artificial intelligence to automate tasks by utilizing a set of defined tools. The tool controller component manages these integrations, acting as the interface that governs how agents interact with and execute specific functions within an organization's workflow.

What does CVE-2026-51915 mean?

This CVE describes an Incorrect Access Control vulnerability, categorized as CWE-284. In simple terms, the software fails to verify that a user has permission to access or change specific tool data. Because the system does not check if a user belongs to the correct organization, it mistakenly allows one user to interact with the private tool metadata belonging to a completely different organization.

How is this vulnerability triggered?

An attacker triggers this by gaining authenticated access to the system and then making specific requests to the tool controller API. The bug occurs when the application receives a request for a tool ID that does not belong to the caller's organization. Notably, the vulnerability is not triggered by public access; it requires an active, authenticated user account within the platform to initiate the unauthorized request.

Is my deployment at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a 'Likely' concern because the tool controller functions as a web-based API. These services are frequently deployed in internet-facing configurations to enable remote access and external integrations. If your SuperAGI instance is reachable over the internet, it is more easily accessible to remote attackers than internal-only services.

What should I do if I use this software?

First, identify all active deployments of TransformerOptimus SuperAGI within your environment. Verify whether your agentic applications handle sensitive tool configurations or metadata. Once identified, assign clear ownership of these systems to your application teams and assess their network reachability to determine the urgency of isolating the tool controller from unauthorized access.

References