CVE-2026-103012: Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-103012
- Published
- Record updated
Summary
Claude Code selected an API key stored on the device, such as one from an earlier `/login` or written into its configuration, over the user's valid Claude Enterprise or Team sign-in when fetching server-managed settings. If the settings endpoint rejected that key, the session ran without the organization's policy, or kept applying a stale cached copy, while still operating as the organization's account. Exploitation required local access to a device holding such a key, and the no-policy case also required that no managed settings had been cached. Endpoint-managed (MDM or file-based) settings were not affected. Claude for Enterprise was affected from version 2.0.68, and Claude for Work (Team) from version 2.1.38.
Mitigation
Users on standard Claude Code auto-update have already received the fix. Users performing manual updates are advised to update to version 2.1.260 or later.
Related items
- InfoAnthropic’s AI gave Philadelphia police a fake tip about an unsolved homicideSame vendor · The Verge (AI)
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer
- InfoAnthropic Launches Free AI Vulnerability Scanner for Open-Source ProjectsSame vendor · The Hacker News
- InfoAnthropic bans users from being 'cruel' to its AI systemsSame vendor · BBC Technology
- InfoThe Download: AI’s refusal problem and weight-loss drug side effectsSame vendor · MIT Technology Review