Authorization Bypass in TransformerOptimus SuperAGI by Vendor
CVE-2026-6586
Key Information:
- Vendor
Transformeroptimus
- Status
- Vendor
- CVE Published:
- 19 April 2026
Badges
What is CVE-2026-6586?
An authorization bypass vulnerability has been discovered in the SuperAGI product from TransformerOptimus. This security flaw affects the get_budget and update_budget functions within the budget.py file of the Budget Endpoint component. Exploiting this vulnerability allows unauthorized manipulation of budget data, which can be executed remotely. Public exploits are available, raising concerns for potential attackers. Despite prior communication efforts, the vendor has not responded regarding this disclosure.
Affected Version(s)
SuperAGI 0.0.1
SuperAGI 0.0.2
SuperAGI 0.0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
