Broken Object-Level Authorization in SuperPlane Affecting Multiple Organizations
CVE-2026-57510

8.7HIGH

Key Information:

Vendor
CVE Published:
28 July 2026

What is CVE-2026-57510?

SuperPlane prior to version 0.27.0 is affected by a serious broken object-level authorization vulnerability in its CanvasService gRPC handlers. This flaw allows authenticated users with viewer-level access to one organization to exploit improperly scoped resources, leading to unauthorized access across organizational boundaries. By crafting requests with arbitrary UUIDs for canvases or queues, attackers can read cross-tenant execution histories, disrupt workflows, write queue items, and eliminate canvases belonging to other organizations. Such vulnerabilities can severely compromise security and data integrity in multi-tenant environments.

Affected Version(s)

superplane 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Katriel Moses
VulnCheck
.