CVE-2026-57510
SuperPlane < 0.27.0 Broken Object Level Authorization via CanvasService gRPC
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to access resources belonging to other organizations by supplying arbitrary canvas or queue UUIDs without organization scoping. Attackers can read cross-tenant execution history and event payloads containing sensitive secrets, write queue items and canvas events into victim organizations, delete arbitrary canvases, and disrupt automation workflows across tenant boundaries.
| CWE | CWE-639 |
| Vendor | superplanehq |
| Product | superplane |
| Published | Jul 28, 2026 |
| Last Updated | Jul 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for superplanehq superplane
Be the first to know when new high vulnerabilities affecting superplanehq superplane are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
superplanehq / superplane
0 < 0.27.0
References
github.com: https://github.com/superplanehq/superplane/releases/tag/v0.27.0 github.com: https://github.com/superplanehq/superplane/pull/5635 github.com: https://github.com/superplanehq/superplane/commit/3e45cf4f1b5f1be9fbbfd90c97960a73f00f897b vulncheck.com: https://www.vulncheck.com/advisories/superplane-broken-object-level-authorization-via-canvasservice-grpc
Credits
Katriel Moses VulnCheck