Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

TransformerOptimus SuperAGI update_organisation function allows unauthorized access

CVE-2026-6585
Summary

A security issue in TransformerOptimus SuperAGI versions up to 0.0.14 allows attackers to bypass authorization controls for updating organisation data. This means an attacker can potentially make changes to organisation information without proper permission. It's recommended to update to the latest version of TransformerOptimus SuperAGI to fix this issue.

Original title
A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This issue affects the function update_organisation of the file superagi/controllers/organisation.py of the component Org...
Original description
A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This issue affects the function update_organisation of the file superagi/controllers/organisation.py of the component Organisation Update Endpoint. This manipulation of the argument organisation_id causes authorization bypass. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0 5.5
nvd CVSS3.1 5.4
nvd CVSS4.0 5.3
Vulnerability type
CWE-285 Improper Authorization
CWE-639 Authorization Bypass Through User-Controlled Key
Published: 20 Apr 2026 · Updated: 20 Apr 2026 · First seen: 20 Apr 2026