Executive brief
SuperPlane, an automation and workflow platform, contains a security flaw in how it handles data requests between different organizations. An authorized user in one organization could exploit this to view, modify, or delete sensitive data and automation workflows belonging to other organizations. This could lead to the exposure of private secrets, disruption of business operations, and unauthorized access to cross-tenant execution histories.
Technical details
A broken object-level authorization (BOLA) vulnerability exists in SuperPlane's CanvasService gRPC handlers prior to version 0.27.0. The flaw stems from a lack of organization-level scoping when processing canvas or queue UUIDs. An authenticated attacker with viewer-level access to their own organization can supply arbitrary UUIDs to access resources belonging to other tenants. This allows for reading cross-tenant execution histories and event payloads (which may contain secrets), writing unauthorized queue items, deleting canvases, and disrupting workflows. The issue was addressed in version 0.27.0 by centralizing gRPC error handling and removing legacy canvas plumbing.
Affected products
- superplanehq SuperPlane < 0.27.0
Timeline
- 2026-06-22: patched: Fixes merged into main branch via PR 5635
- 2026-06-30: patched: Version 0.27.0 released
- 2026-07-28: advisory: CVE-2026-57510 published
References
- https://github.com/superplanehq/superplane/commit/3e45cf4f1b5f1be9fbbfd90c97960a73f00f897b
- https://github.com/superplanehq/superplane/pull/5635
- https://github.com/superplanehq/superplane/releases/tag/v0.27.0
- https://www.vulncheck.com/advisories/superplane-broken-object-level-authorization-via-canvasservice-grpc