{"data":{"id":"7d16165a-a9b6-47dd-b459-5da3bb2e53fc","title":"CVE-2026-103012: Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its…","summary":"Claude Code selected an API key stored on the device, such as one from an earlier `/login` or written into its configuration, over the user's valid Claude Enterprise or Team sign-in when fetching server-managed settings. If the settings endpoint rejected that key, the session ran without the organization's policy, or kept applying a stale cached copy, while still operating as the organization's account. Exploitation required local access to a device holding such a key, and the no-policy case also required that no managed settings had been cached. Endpoint-managed (MDM or file-based) settings were not affected. Claude for Enterprise was affected from version 2.0.68, and Claude for Work (Team) from version 2.1.38.","solution":"Users on standard Claude Code auto-update have already received the fix. Users performing manual updates are advised to update to version 2.1.260 or later.","labels":["security","industry"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103012","publishedAt":"2026-09-30T12:17:12.303Z","cveId":"CVE-2026-103012","cweIds":["CWE-696"],"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":["Anthropic"],"affectedVendorsRaw":["Claude Code","Claude Enterprise","Claude for Work"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"Claude Code stored API key overrides organization policy sign-in","headlinePromptVersion":"h1","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00105,"epssCheckedAt":"2026-10-10T06:42:00.270Z","kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:43:06.184Z","patchAvailable":null,"disclosureDate":"2026-09-30T12:17:12.303Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.93,"researchCategory":null,"atlasIds":["AML.T0010"]}}