CVE-2026-66027
Last modified
CVE-2026-66027 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's session queue, causing the background drainer to forward malicious messages to the victim's running AI agent with the victim's credentials and permissions.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's session queue, causing the background drainer to forward malicious messages to the victim's running AI agent with the victim's credentials and permissions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| kortix-ai | suna | < 0.9.102 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-66027?
How severe is CVE-2026-66027?
How do I fix CVE-2026-66027?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-66013OpenRemote before 1.26.2 contains an authentication bypass v…9.3
- CVE-2026-66014JFrog Artifactory contains an authentication handling weakne…9.8
- CVE-2026-66015An authenticated privilege-escalation vulnerability in JFrog…7.2
- CVE-2026-66016Under specific self-hosted Helm configurations, generated TL…6.7
- CVE-2026-66018Build readers can access another repository's environment pr…6.5
- CVE-2026-6602A vulnerability was found in rickxy Hospital Management Syst…7.3
- CVE-2026-66028Ekushey Project Manager CRM through version 5.0 contains a m…7.1
- CVE-2026-66029Ekushey Project Manager CRM through version 5.0 contains a s…5.4
- CVE-2026-6603A vulnerability was determined in modelscope agentscope up t…7.3
- CVE-2026-66030Ekushey Project Manager CRM through version 5.0 ccontains a …5.4
- CVE-2026-66031Ekushey Project Manager CRM through version 5.0 contains a s…5.4
- CVE-2026-66032libssh2 through 1.11.1, fixed in commit 5e47761, contains a …8.8
Are you affected by CVE-2026-66027?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
