PT-2026-33655 · Transformeroptimus · Superagi

Eric-Z

·

Published

2026-04-19

·

Updated

2026-04-20

·

CVE-2026-6586

CVSS v3.1

6.3

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get budget/update budget of the file superagi/controllers/budget.py of the component Budget Endpoint. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Exploit

Fix

IDOR

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-6586

Affected Products

Superagi