top of page
perceptive_background_267k.jpg

SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with view…

Published:

28 July 2026 at 00:00:00

Alert date:

28 July 2026 at 23:02:19

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Cloud & Virtualization, Enterprise Applications

SuperPlane versions before 0.27.0 contain a broken object-level authorization (BOLA) vulnerability in the CanvasService gRPC handlers. Authenticated users with viewer-level access to one organization can access resources of other organizations by supplying arbitrary canvas or queue UUIDs without proper organization scoping. The vulnerability enables cross-tenant attacks including reading execution history and sensitive secrets, writing queue items and canvas events into victim organizations, and deleting arbitrary canvases. The flaw disrupts automation workflows across tenant boundaries, making it a significant multi-tenant isolation failure. The vulnerability was fixed in SuperPlane v0.27.0 via a commit that introduces proper organization-scoped authorization checks. References and patches are available via GitHub commits, pull requests, and the official release. The issue is also documented by VulnCheck in their advisories. Organizations using SuperPlane in multi-tenant environments should upgrade immediately to v0.27.0.

Technical details

Mitigation steps:

Affected products:

SuperPlane before 0.27.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page