{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/superplane/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-57510"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SuperPlane \u003c 0.27.0"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","api-security","saas","cloud","multi-tenancy","grpc","cve"],"_cs_type":"advisory","_cs_vendors":["SuperPlane"],"content_html":"\u003cp\u003eCVE-2026-57510 details a broken object-level authorization vulnerability affecting SuperPlane versions prior to 0.27.0. This flaw resides within the CanvasService gRPC handlers, which are responsible for managing canvas and queue resources. An authenticated user with legitimate viewer-level access to one organization can exploit this vulnerability to gain unauthorized access to resources belonging to other organizations. By supplying arbitrary canvas or queue Universally Unique Identifiers (UUIDs) without proper organization scoping, an attacker can bypass access controls. This allows for reading sensitive cross-tenant execution history and event payloads that may contain secrets, writing unauthorized queue items and canvas events into victim organizations, deleting arbitrary canvases, and ultimately disrupting critical automation workflows across different tenant environments. The vulnerability poses a significant risk to data confidentiality, integrity, and system availability in multi-tenant SuperPlane deployments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains legitimate authenticated viewer-level access to a SuperPlane organization.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies the target SuperPlane instance is running a version prior to 0.27.0.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts gRPC requests targeting the CanvasService handlers.\u003c/li\u003e\n\u003cli\u003eThe attacker includes arbitrary canvas or queue UUIDs in these requests that do not belong to their authorized organization.\u003c/li\u003e\n\u003cli\u003eDue to the broken object-level authorization, the CanvasService gRPC handlers process these requests without enforcing organization-level scoping.\u003c/li\u003e\n\u003cli\u003eThe attacker successfully accesses resources (e.g., execution history, event payloads) belonging to other organizations.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages this access to read sensitive secrets, write malicious queue items or canvas events, or delete critical canvases.\u003c/li\u003e\n\u003cli\u003eThe attacker disrupts automation workflows across tenant boundaries, achieving data collection and system impact objectives.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-57510 can lead to severe consequences for SuperPlane deployments utilizing versions prior to 0.27.0. Attackers can read sensitive cross-tenant execution history and event payloads, which may contain critical secrets, compromising data confidentiality across multiple organizations. Furthermore, the vulnerability enables unauthorized modification of data by allowing attackers to write queue items and canvas events into victim organizations. The ability to delete arbitrary canvases can result in significant data loss and disruption. Critically, this flaw can be leveraged to disrupt automation workflows across tenant boundaries, leading to service degradation, operational outages, and potentially widespread business impact for affected SuperPlane customers. The broad scope of potential impact makes this a high-severity threat.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade all SuperPlane installations to version 0.27.0 or later to patch CVE-2026-57510.\u003c/li\u003e\n\u003cli\u003eImplement robust monitoring for unusual gRPC activity within your SuperPlane environment, specifically looking for attempts to access or manipulate canvas or queue UUIDs that are not associated with the authenticated user's organization.\u003c/li\u003e\n\u003cli\u003eReview access logs for any indications of cross-tenant resource access by single-tenant authenticated users, particularly after patching CVE-2026-57510.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T20:22:47Z","date_published":"2026-07-28T20:22:47Z","id":"https://feed.craftedsignal.io/briefs/2026-07-superplane-auth-bypass/","summary":"A critical broken object-level authorization vulnerability in SuperPlane's CanvasService gRPC handlers, tracked as CVE-2026-57510, allows authenticated users with viewer-level access to bypass organization scoping and access resources across tenant boundaries, leading to data collection and system impact.","title":"SuperPlane Broken Object-Level Authorization Vulnerability (CVE-2026-57510)","url":"https://feed.craftedsignal.io/briefs/2026-07-superplane-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - SuperPlane","version":"https://jsonfeed.org/version/1.1"}