CVE-2026-6582Disclosure

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function get_vector_db_details of the file superagi/controllers/vector_dbs.py of the component Vector Database Management Endpoint. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-19); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-19: 1Mentions · 2026-04-20: 1Mentions · 2026-04-28: 1PoC Mentioned / Linked · 2026-04-28: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-28: 104-1904-2004-28
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-191
Disclosure1
2026-04-201
General1
2026-04-281
Patch1
Full discourse3 posts
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH SEVERITY: CVE-2026-6582 (CVSS 7.3) TransformerOptimus SuperAGI ≤0.0.14 - Missing authentication in vector DB endpoint allows remote exploitation. Exploit code public. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/ps5LBFja5z

    Post summary

    The tweet highlights a high‑severity vulnerability (CVE‑2026‑6582) with a publicly available exploit and urges immediate patching.

    0000063
    27 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6582 A flaw has been found in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function get_vector_db_details of the file superagi/controllers/vector_… https://www.cve.org/CVERecord?id=CVE-2026-6582

    Post summary

    The text reports a newly discovered flaw in TransformerOptimus SuperAGI up to version 0.0.14, affecting the get_vector_db_details function, but does not provide further technical details, patches, or exploitation evidence.

    00000136
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6582 Authentication Bypass in TransformerOptimus SuperAGI Vector Database Management Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6582

    Post summary

    The text announces CVE‑2026‑6582, describing an Authentication Bypass in the TransformerOptimus SuperAGI Vector Database Management Endpoint, and provides a link for further details.

    0000054
    4.0K followersView on X

Explore more