CVE-2026-103012
Received Received - Intake

Session Policy Bypass in Claude Code

Vulnerability report for CVE-2026-103012, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: 98a01053-8a31-4f6d-9aa9-252be161adc6

Description

Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the organization's server-managed settings, even though the session itself authenticated with the Enterprise or Team account. When the settings endpoint rejected that stored key, the session started without the organization's server-managed policy (such as permission deny rules, model restrictions and managed-only locks) or, if a previously cached copy existed on the machine, kept applying that stale copy without receiving later policy changes β€” while continuing to operate as the organization's account. Triggering this required local access to a device with such a stored API key; the no-policy case additionally required that no managed settings had previously been cached. Endpoint-managed (MDM or file-based) settings were not affected. Claude for Enterprise organizations were affected from version 2.0.68; Claude for Work (Team) organizations from version 2.1.38, when server-managed settings became available to them. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.1.260 or later. Thank you to Tamas Voros / NVIDIA AI Red Team for reporting this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
claude_code claude From 2.0.68 (inc)
claude_code claude From 2.1.38 (inc)
claude_code claude to 2.1.260 (exc)
anthropics claude_code From 2.0.68 (inc) to 2.1.260 (exc)
anthropics claude_code From 2.1.38 (inc) to 2.1.260 (exc)
anthropics claude_code 2.1.260

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-696 The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Claude Code selected an API key stored locally ahead of a valid user sign-in when fetching server-managed settings. This caused the session to either operate without the organization's managed policies or continue using a stale cached copy of those policies. The issue required local access to a device with a stored API key and only affected users who hadn't previously cached managed settings.

Detection Guidance

This vulnerability requires local access to a device with a stored API key and can only be detected by checking if the system is running affected versions of Claude Code (2.0.68 to 2.1.259) without the latest patch. Verify the installed version using the application's version command or update logs.

Impact Analysis

An attacker with local access to a device could bypass organization policies like permission rules or model restrictions. The session might operate without current policies or use outdated cached policies, potentially allowing unauthorized actions under the organization's account.

Mitigation Strategies

Update Claude Code to version 2.1.260 or later immediately. If using auto-updates, ensure they are enabled. For manual updates, download and install the latest version from the official source.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103012. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart