CVE-2026-57510
HIGHSuperPlane < 0.27.0 Broken Object Level Authorization via CanvasService gRPC
Title source: cnaDescription
SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to access resources belonging to other organizations by supplying arbitrary canvas or queue UUIDs without organization scoping. Attackers can read cross-tenant execution history and event payloads containing sensitive secrets, write queue items and canvas events into victim organizations, delete arbitrary canvases, and disrupt automation workflows across tenant boundaries.
References (4)
Core 4
Core References
Release Notes release-notes
Release Notes
https://github.com/superplanehq/superplane/releases/tag/v0.27.0
Patch patch
Patch Commit
https://github.com/superplanehq/superplane/commit/3e45cf4f1b5f1be9fbbfd90c97960a73f00f897b
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/superplane-broken-object-level-authorization-via-canvasservice-grpc
Scores
CVSS v3
8.8
EPSS
0.0034
EPSS Percentile
26.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-639
Status
published
Products (1)
superplanehq/superplane
< 0.27.0
Published
Jul 28, 2026
Tracked Since
Jul 29, 2026