What is CVE-2026-57510?
SuperPlane versions before 0.27.0 contain a broken object-level authorization vulnerability in CanvasService gRPC handlers. This allows authenticated users with viewer-level access to one organization to access resources belonging to other organizations by supplying arbitrary UUIDs. Immediate upgrade to version 0.27.0 or later is recommended.
Azərbaycanca: SuperPlane platformasının 0.27.0 versiyasından əvvəlki versiyalarında CanvasService gRPC handlerlərində 'broken object-level authorization' zəifliyi mövcuddur. Bu, bir təşkilatda yalnız izləyici səviyyəli girişi olan autentifikasiya olunmuş istifadəçilərə ixtiyari UUID-lər təqdim etməklə digər təşkilatlara məxsus resurslara icazəsiz giriş imkanı verir. Dərhal 0.27.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Who can exploit the broken object-level authorization vulnerability in the SuperPlane platform?
This vulnerability can be exploited by authenticated users who have only viewer-level access within one organization.
Which version is recommended to upgrade to in order to fix CVE-2026-57510?
An immediate upgrade to SuperPlane version 0.27.0 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.