CVE-2026-57510
Published Jul 28, 2026SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to…
- evidence mentions
- 4
- Buzz score
- 22.6