
Leftover Claude Code API keys can drop your org deny-list. CVE-2026-103012 (GHSA Sep 29 / CVE Sep 30): @AnthropicAI Claude Code preferred a locally stored API key (old /login or config write) when fetching server-managed settings, even though the session itself authenticated with Claude Enterprise or Team. If that leftover key was rejected, the CLI started with no org policy (deny rules, model locks, managed-only) or kept a stale cache, while still operating as the org account. Endpoint-managed MDM / file settings were not affected. Enterprise hit from 2.0.68; Team from 2.1.38. Reported by Tamas Voros / NVIDIA AI Red Team (@nvidia). Patched in 2.1.260 (auto-update already shipping). Tonight: 1. Confirm Claude Code is on 2.1.260+ (manual installs: update now) 2. Prefer endpoint-managed settings (MDM or managed-settings.json) over server-only delivery 3. Purge leftover API keys from developer machines after Enterprise/Team cutover; set forceRemoteSettingsRefresh where a fail-closed start is required https://github.com/anthropics/claude-code/security/advisories/GHSA-gfvf-j8jh-jxxw
