CVE-2026-66027: Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated at
Summary
Suna versions before 0.9.102 have a broken access control vulnerability (a flaw where the system fails to properly verify who should be allowed to access data) in its message queue API (the interface for managing task queues). Authenticated attackers can exploit missing ownership checks to read, delete, or manipulate message queues belonging to other users, including injecting malicious prompts into another user's AI agent session to execute commands with that user's permissions.
Solution / Mitigation
Update Suna to version 0.9.102 or later.
Vulnerability Details
8.3(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
network
low
low
none
July 24, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-66027
First tracked: July 24, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 85%