---
id: CVE-2026-51867
title: >-
  agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in
  next/src/server/api/routers/agentRouter.ts
summary: >-
  agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in
  next/src/server/api/routers/agentRouter.ts. An externally reachable path
  accepts a caller-selected object or tenant identifier and reaches a
  data-access operation without a vi…
severity: none
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:12.600'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-51867'
references:
  - url: 'https://gist.github.com/Ro1ME/62547f81c244f273b66755dad63a8673'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.845Z'
---

## Overview

agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
