Broken Object-Level Authorization in SuperPlane Affecting Multiple Organizations
CVE-2026-57510
8.7HIGH
What is CVE-2026-57510?
SuperPlane prior to version 0.27.0 is affected by a serious broken object-level authorization vulnerability in its CanvasService gRPC handlers. This flaw allows authenticated users with viewer-level access to one organization to exploit improperly scoped resources, leading to unauthorized access across organizational boundaries. By crafting requests with arbitrary UUIDs for canvases or queues, attackers can read cross-tenant execution histories, disrupt workflows, write queue items, and eliminate canvases belonging to other organizations. Such vulnerabilities can severely compromise security and data integrity in multi-tenant environments.
Affected Version(s)
superplane 0
