CVE-2026-103012

LOWCVSS 2.0 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the organization's server-managed settings, even though the session itself authenticated with the Enterprise or Team account. When the settings endpoint rejected that stored key, the session started without the organization's server-managed policy (such as permission deny rules, model restrictions and managed-only locks) or, if a previously cached copy existed on the machine, kept applying that stale copy without receiving later policy changes — while continuing to operate as the organization's account. Triggering this required local access to a device with such a stored API key; the no-policy case additionally required that no managed settings had previously been cached. Endpoint-managed (MDM or file-based) settings were not affected. Claude for Enterprise organizations were affected from version 2.0.68; Claude for Work (Team) organizations from version 2.1.38, when server-managed settings became available to them. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.1.260 or later. Thank you to Tamas Voros / NVIDIA AI Red Team for reporting this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-696

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-01: 110-01
Referenced assets1 URL
Full discourse1 post
  • hackerlogs@hackerlogs

    Leftover Claude Code API keys can drop your org deny-list. CVE-2026-103012 (GHSA Sep 29 / CVE Sep 30): @AnthropicAI Claude Code preferred a locally stored API key (old /login or config write) when fetching server-managed settings, even though the session itself authenticated with Claude Enterprise or Team. If that leftover key was rejected, the CLI started with no org policy (deny rules, model locks, managed-only) or kept a stale cache, while still operating as the org account. Endpoint-managed MDM / file settings were not affected. Enterprise hit from 2.0.68; Team from 2.1.38. Reported by Tamas Voros / NVIDIA AI Red Team (@nvidia). Patched in 2.1.260 (auto-update already shipping). Tonight: 1. Confirm Claude Code is on 2.1.260+ (manual installs: update now) 2. Prefer endpoint-managed settings (MDM or managed-settings.json) over server-only delivery 3. Purge leftover API keys from developer machines after Enterprise/Team cutover; set forceRemoteSettingsRefresh where a fail-closed start is required https://github.com/anthropics/claude-code/security/advisories/GHSA-gfvf-j8jh-jxxw

    1000086
    17 followersView on X

Explore more