CVE-2026-103012: Low severity Anthropic Claude Code vulnerability

Published Sep 30, 2026
·
Updated

Claude Code selected an API key stored by Claude Code, for example from an earlier /login or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the organization's server-managed settings, even though the session itself authenticated with the Enterprise or Team account. When the settings endpoint rejected that stored key, the session started without the organization's server-managed policy (such as permission deny rules, model restrictions and managed-only locks) or, if a previously cached copy existed on the machine, kept applying that stale copy without receiving later policy changes — while continuing to operate as the organization's account. Triggering this required local access to a device with such a stored API key; the no-policy case additionally required that no managed settings had previously been cached. Endpoint-managed (MDM or file-based) settings were not affected. Claude for Enterprise organizations were affected from version 2.0.68; Claude for Work (Team) organizations from version 2.1.38, when server-managed settings became available to them.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.1.260 or later.

Thank you to Tamas Voros / NVIDIA AI Red Team for reporting this issue.

Affected Software

2 affected components
Anthropic Claude Code>=2.0.68<2.1.260
Anthropic Claude Code>=2.1.38<2.1.260

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Claude Code to a version that resolves this vulnerability.

    Fixed in 2.1.260

Event History

Sep 30, 2026
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
DescriptionWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Claude for Enterprise organizations are affected from version 2.0.68, and Claude for Work (Team) organizations are affected from version 2.1.38, when server-managed settings became available. Endpoint-managed settings delivered through MDM or files are not affected.

2

What access is needed to trigger the issue?

An attacker needs local access to a device that has an API key stored by Claude Code, such as one retained from an earlier /login or written directly to its configuration. The session can still be authenticated with the organization's Enterprise or Team account.

3

When would organization policy be absent rather than stale?

The no-policy outcome requires both rejection of the stored API key by the settings endpoint and no previously cached managed settings on the machine. If managed settings were already cached, Claude Code can continue using that stale policy instead of receiving later changes.

4

What controls can be bypassed in an affected session?

The affected session may operate without the organization's current server-managed policy, including permission deny rules, model restrictions, and managed-only locks. It continues to operate as the organization's account while this occurs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203