Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

TransformerOptimus SuperAGI Allows Unauthorized Access to Budget Data

CVE-2026-6586
Summary

A security issue in TransformerOptimus SuperAGI allows an attacker to bypass authorization checks and potentially access budget data without permission. This could happen if an attacker exploits a publicly available exploit. Affected users should update to the latest version of TransformerOptimus SuperAGI to fix the issue.

Original title
A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/controllers/budget.py of the component Budget Endp...
Original description
A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/controllers/budget.py of the component Budget Endpoint. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0 6.5
nvd CVSS3.1 6.3
nvd CVSS4.0 5.3
Vulnerability type
CWE-285 Improper Authorization
CWE-639 Authorization Bypass Through User-Controlled Key
Published: 20 Apr 2026 · Updated: 20 Apr 2026 · First seen: 20 Apr 2026