SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-57510

HIGH · CVSS 8.8 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

SuperPlane versions prior to 0.27.0 are vulnerable due to a broken object-level authorization flaw in the CanvasService gRPC handlers, allowing authenticated users with viewer-level access to access and manipulate resources across different organizations. This vulnerability enables attackers to read sensitive execution histories, write unauthorized queue items, delete canvases, and disrupt workflows, posing significant risks to data integrity and confidentiality. Organizations using SuperPlane should prioritize immediate remediation to mitigate potential cross-tenant attacks and safeguard sensitive information.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57510
Severity
HIGH
CVSS
8.8
EPSS
0.34%

Original NVD Description

SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to access resources belonging to other organizations by supplying arbitrary canvas or queue UUIDs without organization scoping. Attackers can read cross-tenant execution history and event payloads containing sensitive secrets, write queue items and canvas events into victim organizations, delete arbitrary canvases, and disrupt automation workflows across tenant boundaries.