PT-2026-33653 · Superagi · Superagi

Eric-Z

·

Published

2026-04-19

·

Updated

2026-04-20

·

CVE-2026-6584

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions TransformerOptimus SuperAGI versions prior to 0.0.15
Description An authorization bypass exists in the User Update Endpoint within the update user() function of the superagi/controllers/user.py file. A remote attacker can manipulate the user id argument to bypass authorization controls.
Recommendations Update to a version later than 0.0.14. As a temporary workaround, restrict access to the user id argument in the User Update Endpoint.

Exploit

Fix

IDOR

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-6584

Affected Products

Superagi