CVE-2026-35603General(anthropic / claude_code)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without validating directory ownership or access permissions. Because the ProgramData directory is writable by non-administrative users by default and the ClaudeCode subdirectory was not pre-created or access-restricted, a low-privileged local user could create this directory and place a malicious configuration file that would be automatically loaded for any user launching Claude Code on the same machine. Exploiting this would have required a shared multi-user Windows system and a victim user to launch Claude Code after the malicious configuration was placed. This issue has been fixed on version 2.1.75.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-426

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • claude_code
  • windows

Threat summary

  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 4 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-04-18); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
claude_codewindows

1 version affected across 2 products

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-04-18: 2Mentions · 2026-06-18: 2Mentions · 2026-09-12: 1Mentions · 2026-10-03: 1Technical Details · 2026-04-18: 104-1806-1809-1210-03
Signal classification2 categories
General
480.0%
Disclosure
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-182
General2
2026-06-182
General2
2026-09-121
Disclosure1
Full discourse6 posts
  • Ilan Kalendarov@IKalendarov
    General

    If you received this Anthropic email, you were probably affected by a vulnerability we found. CVE-2026-35603 👇 https://t.co/otQKOtkD0w

    Post summary

    The tweet notes that recipients of a specific Anthropic email were likely affected by CVE-2026-35603, but offers no technical or mitigation details.

    1001228.6K
    727 followersView on X
  • Chamse@IAMChamse

    Last night I read CVE-2026-35603. An AI coding tool trusts a config file in a folder anyone on a shared machine can write to, so every user on that box runs the attacker's code. I went and looked at where my agent configs load from, and who can write there.

    0002036
    32 followersView on X
  • Ilan Kalendarov@IKalendarov
    General

    Full research: https://cymulate.com/blog/cve-2026-35603-ai-coding-tools-privilege-escalation/

    Post summary

    The provided text contains only a link to a research blog post about CVE‑2026‑35603 with no additional information on PoC, exploit, or mitigation details.

    00020101
    727 followersView on X
  • Ilia Gusev@persikbl
    Disclosure

    An agent, fully inside its sandbox, writes a file the boundary was never designed to police - a .claude hook, a .vscode task config, a modified venv. Something outside the sandbox reads and executes it later. CVE-2026-35603 and CVE-2026-48124 came out of that wave.

    Post summary

    The text announces the appearance of CVE‑2026‑35603 and CVE‑2026‑48124 linked to sandbox escape via unseen file types but offers no further technical or practical information.

    1000036
    10 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-35603 Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode… https://www.cve.org/CVERecord?id=CVE-2026-35603

    Post summary

    The text briefly mentions a CVE and references a version and a configuration path, but provides no actionable details about exploitation, patches, or technical specifics.

    00000205
    57.2K followersView on X
  • DailyCVE@dailycve
    General

    🟠 Claude Code, Insecure System-Wide Configuration Loading, #CVE-2026-35603 (Moderate) https://dailycve.com/claude-code-insecure-system-wide-configuration-loading-cve-2026-35603-moderate/

    Post summary

    The provided text only gives a headline and a link, with minimal technical details about CVE‑2026‑35603 and no evidence of exploitation, PoC, or patch information.

    0000048
    181 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appanthropicclaude_code-node.js-
OSmicrosoftwindows---

Explore more