CVE-2026-6585: TransformerOptimus SuperAGI Organisation Update Endpoint organisation.py update_organisation authorization
A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This issue affects the function updateorganisation of the file superagi/controllers/organisation.py of the component Organisation Update Endpoint. This manipulation of the argument organisationid causes authorization bypass. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6585?
CVE-2026-6585 is classified as a vulnerability affecting authorization in the TransformerOptimus SuperAGI up to version 0.0.14.
How do I fix CVE-2026-6585?
To remediate CVE-2026-6585, upgrade TransformerOptimus SuperAGI to version 0.0.15 or later.
What component is affected by CVE-2026-6585?
CVE-2026-6585 affects the update_organisation function in the organisation.py file of TransformerOptimus SuperAGI.
Which versions of TransformerOptimus SuperAGI are affected by CVE-2026-6585?
Versions up to and including 0.0.14 of TransformerOptimus SuperAGI are affected by CVE-2026-6585.
What type of vulnerability is CVE-2026-6585?
CVE-2026-6585 is an authorization vulnerability that can lead to improper access controls in the affected software.