PT-2026-33655 · Superagi · Superagi

Eric-Z

·

Published

2026-04-19

·

Updated

2026-04-20

·

CVE-2026-6586

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TransformerOptimus SuperAGI versions prior to 0.0.15
Description An authorization bypass exists in the Budget Endpoint component. The issue is located within the get budget() and update budget() functions of the file superagi/controllers/budget.py, allowing a remote attacker to bypass authorization controls.
Recommendations Update to a version newer than 0.0.14. As a temporary workaround, restrict access to the get budget() and update budget() functions until a patch is applied.

Exploit

Fix

Improper Authorization

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-6586

Affected Products

Superagi