


Perceptive Security
SOC/SIEM Consultancy

SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with view…
Published:
28 juli 2026 om 00:00:00
Alert date:
28 juli 2026 om 23:02:19
Source:
nvd.nist.gov
Identity & Access, Cloud & Virtualization, Enterprise Applications
SuperPlane versions before 0.27.0 contain a broken object-level authorization (BOLA) vulnerability in the CanvasService gRPC handlers. Authenticated users with viewer-level access to one organization can access resources of other organizations by supplying arbitrary canvas or queue UUIDs without proper organization scoping. The vulnerability enables cross-tenant attacks including reading execution history and sensitive secrets, writing queue items and canvas events into victim organizations, and deleting arbitrary canvases. The flaw disrupts automation workflows across tenant boundaries, making it a significant multi-tenant isolation failure. The vulnerability was fixed in SuperPlane v0.27.0 via a commit that introduces proper organization-scoped authorization checks. References and patches are available via GitHub commits, pull requests, and the official release. The issue is also documented by VulnCheck in their advisories. Organizations using SuperPlane in multi-tenant environments should upgrade immediately to v0.27.0.
Technical details
Mitigation steps:
Affected products:
SuperPlane before 0.27.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-57510
https://github.com/superplanehq/superplane/commit/3e45cf4f1b5f1be9fbbfd90c97960a73f00f897b
https://github.com/superplanehq/superplane/pull/5635
https://github.com/superplanehq/superplane/releases/tag/v0.27.0
https://www.vulncheck.com/advisories/superplane-broken-object-level-authorization-via-canvasservice-grpc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
