天下漏洞,尽知其名
MEDIUM

CVE-2026-103012 Claude Code 身份验证绕过漏洞

影响会话可能绕过企业策略运行,导致权限管控失效

MEDIUM
暂无 CVSS 评分
AI 研判

Claude Code 在获取组织服务器托管设置时,会优先使用本地存储的 API key,而非当前已通过 Claude Enterprise 或 Team 账号认证的会话。当该 API key 被设置端点拒绝时,会话会在缺少组织托管策略的情况下启动,或继续沿用机器上缓存的旧策略。

影响范围

Claude Code

Claude for Enterprise 组织自 2.0.68 版本起受影响;Claude for Work(Team)组织自 2.1.38 版本起受影响。端点托管(MDM 或基于文件)的设置不受影响。

漏洞详情

该漏洞属于身份验证绕过/策略绕过类问题。成因是客户端在选择认证凭据时,将本地存储的 API key 置于当前企业账号会话之上。攻击者需具备对存有该 API key 设备的本地访问权限,即可使会话在无托管策略或使用过期策略的情况下运行,同时仍以组织账号身份操作。

利用条件与风险

利用前提是攻击者能本地访问存有此类 API key 的设备;无策略场景还要求此前未缓存过托管设置。实战中可导致权限拒绝规则、模型限制等企业管控措施失效。

修复建议

使用标准 Claude Code 自动更新的用户已收到修复。建议升级至已修复版本,并清理本地存储的旧 API key 与缓存设置;暂无其他公开缓解信息。

原始情报

Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user’s valid Claude Enterprise or Team sign-in when fetching the organization’s server-managed settings, even though the session itself authenticated with the Enterprise or Team account. When the settings endpoint rejected that stored key, the session started without the organization’s server-managed policy (such as permission deny rules, model restrictions and managed-only locks) or, if a previously cached copy existed on the machine, kept applying that stale copy without receiving later policy changes — while continuing to operate as the organization’s account. Triggering this required local access to a device with such a stored API key; the no-policy case additionally required that no managed settings had previously been cached. Endpoint-managed (MDM or file-based) settings were not affected. Claude for Enterprise organizations were affected from version 2.0.68; Claude for Work (Team) organizations from version 2.1.38, when server-managed settings became available to them.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.1.260 or later.

Thank you to Tamas Voros / NVIDIA AI Red Team for reporting this issue.