CVE-2026-6586: TransformerOptimus SuperAGI Budget Endpoint budget.py update_budget authorization
A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function getbudget/updatebudget of the file superagi/controllers/budget.py of the component Budget Endpoint. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6586?
CVE-2026-6586 has a critical severity due to improper authorization in the Budget Endpoint that could allow unauthorized access.
How do I fix CVE-2026-6586?
To fix CVE-2026-6586, update TransformerOptimus SuperAGI to version 0.0.15 or later where the vulnerability is patched.
What components are affected by CVE-2026-6586?
CVE-2026-6586 affects the Budget Endpoint functionality in the superagi/controllers/budget.py file of TransformerOptimus SuperAGI.
Who is impacted by CVE-2026-6586?
Users of TransformerOptimus SuperAGI up to version 0.0.14 are impacted by CVE-2026-6586.
What type of vulnerability is CVE-2026-6586?
CVE-2026-6586 is classified as an authorization vulnerability affecting budget management functions.