CVE-2026-6614Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the function get_project/update_project/get_projects_organisation of the file superagi/controllers/project.py. The manipulation results in authorization bypass. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-20: 2Technical Details · 2026-04-20: 104-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-6614 A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the function get_project/update_project/get_projects_… https://www.cve.org/CVERecord?id=CVE-2026-6614

    Post summary

    CVE-2026-6614 has been disclosed for TransformerOptimus SuperAGI up to version 0.0.14, impacting certain project management functions, but no PoC, exploit, or patch details are provided.

    0000087
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6614 Authorization Bypass in TransformerOptimus SuperAGI Up To 0.0.14 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6614 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet simply announces the CVE-2026-6614 vulnerability in TransformerOptimus SuperAGI and links to Vulmon vulnerability and notification pages. No PoC, exploit, or patch details are provided.

    0000049
    4.0K followersView on X

Explore more