{"id":"CVE-2026-103012","details":"Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the organization's server-managed settings, even though the session itself authenticated with the Enterprise or Team account. When the settings endpoint rejected that stored key, the session started without the organization's server-managed policy (such as permission deny rules, model restrictions and managed-only locks) or, if a previously cached copy existed on the machine, kept applying that stale copy without receiving later policy changes — while continuing to operate as the organization's account. Triggering this required local access to a device with such a stored API key; the no-policy case additionally required that no managed settings had previously been cached. Endpoint-managed (MDM or file-based) settings were not affected. Claude for Enterprise organizations were affected from version 2.0.68; Claude for Work (Team) organizations from version 2.1.38, when server-managed settings became available to them.\n\nUsers on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.1.260 or later.\n\nThank you to Tamas Voros / NVIDIA AI Red Team for reporting this issue.","aliases":["GHSA-gfvf-j8jh-jxxw"],"modified":"2026-10-02T03:31:05.114943749Z","published":"2026-09-30T11:30:38.308Z","database_specific":{"cwe_ids":["CWE-696"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103012.json","cna_assigner":"Anthropic"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103012.json"},{"type":"ADVISORY","url":"https://github.com/anthropics/claude-code/security/advisories/GHSA-gfvf-j8jh-jxxw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103012"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/anthropics/claude-code","events":[{"introduced":"0"},{"fixed":"b3f0e501b79fe5cfc8c10d18cf3b0b6715c5c2fb"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"2.0.68"},{"fixed":"2.1.260"}]}}],"versions":["v2.1.259","v2.1.258","v2.1.257","v2.1.252","v2.1.251","v2.1.250","v2.1.248","v2.1.247","v2.1.246","v2.1.245","v2.1.243","v2.1.241","v2.1.240","v2.1.239","v2.1.238","v2.1.237","v2.1.236","v2.1.235","v2.1.234","v2.1.233","v2.1.232","v2.1.231","v2.1.229","v2.1.228","v2.1.227","v2.1.226","v2.1.225","v2.1.224","v2.1.223","v2.1.222","v2.1.221","v2.1.220","v2.1.219","v2.1.218","v2.1.217","v2.1.216","v2.1.215","v2.1.214","v2.1.212","v2.1.211","v2.1.210","v2.1.209","v2.1.208","v2.1.207","v2.1.206","v2.1.205","v2.1.204","v2.1.203","v2.1.202","v2.1.201","v2.1.200","v2.1.199","v2.1.198","v2.1.197","v2.1.196","v2.1.195","v2.1.193","v2.1.191","v2.1.190","v2.1.187","v2.1.186","v2.1.185","v2.1.183","v2.1.181","v2.1.179","v2.1.178","v2.1.177","v2.1.176","v2.1.175","v2.1.174","v2.1.173","v2.1.172","v2.1.170","v2.1.169","v2.1.168","v2.1.167","v2.1.166","v2.1.165","v2.1.163","v2.1.162","v2.1.161","v2.1.160","v2.1.159","v2.1.158","v2.1.157","v2.1.156","v2.1.154","v2.1.153","v2.1.152","v2.1.150","v2.1.149","v2.1.148","v2.1.147","v2.1.146","v2.1.145","v2.1.144","v2.1.143","v2.1.142","v2.1.141","v2.1.140","v2.1.139","v2.1.138","v2.1.137","v2.1.136","v2.1.133","v2.1.132","v2.1.131","v2.1.129","v2.1.128","v2.1.126","v2.1.123","v2.1.122","v2.1.121","v2.1.120","v2.1.119","v2.1.118","v2.1.117","v2.1.116","v2.1.114","v2.1.113","v2.1.112","v2.1.111","v2.1.110","v2.1.109","v2.1.108","v2.1.107","v2.1.105","v2.1.104","v2.1.101","v2.1.98","v2.1.100","v2.1.97","v2.1.96","v2.1.94","v2.1.92","v2.1.91","v2.1.90","v2.1.89","v2.1.88","v2.1.87","v2.1.86","v2.1.85","v2.1.84","v2.1.83","v2.1.81","v2.1.80","v2.1.79","v2.1.78","v2.1.77","v2.1.76","v2.1.75","v2.1.74","v2.1.73","v2.1.72","v2.1.71","v2.1.70","v2.1.69","v2.1.68","v2.1.66","v2.1.63","v2.1.62","v2.1.61","v2.1.59","v2.1.58","v2.1.56","v2.1.55","v2.1.53","v2.1.52","v2.1.51","v2.1.50","v2.1.49","v2.1.47","v2.1.45","v2.1.44","v2.1.42","v2.1.41","v2.1.39","v2.1.38","v2.1.37","v2.1.36","v2.1.34","v2.1.33","v2.1.32","v2.1.31","v2.1.30","v2.1.29","v2.1.12","v2.1.27","v2.1.25","v2.1.23","v2.1.22","v2.1.21","v2.1.20","v2.1.19","v2.1.17","v2.1.16","v2.1.15","v2.1.14","v2.1.11","v2.1.9","v2.1.7","v2.1.6","v2.1.5","v2.1.4","v2.1.3","v2.1.2","v2.1.1","v2.0.76","v2.1.0","v2.0.74","v2.0.73"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103012.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}