CVE-2026-66027

Source
https://cve.org/CVERecord?id=CVE-2026-66027
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66027.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-66027
Published
2026-07-24T15:27:04.682Z
Modified
2026-07-27T04:03:30.897865744Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Suna < 0.9.102 Broken Access Control via Message Queue API
Details

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's session queue, causing the background drainer to forward malicious messages to the victim's running AI agent with the victim's credentials and permissions.

Database specific
{
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66027.json",
    "cwe_ids": [
        "CWE-862"
    ]
}
References

Affected packages

Git / github.com/kortix-ai/suna

Affected ranges

Type
GIT
Repo
https://github.com/kortix-ai/suna
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.9.102"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

Other
dev-latest
v.*
v.0.1.11
v.0.1.9
v0.*
v0.1.0
v0.1.1
v0.1.4
v0.1.8
v0.8.24
v0.8.25
v0.8.26
v0.8.27
v0.8.28
v0.8.29
v0.8.30
v0.8.31
v0.8.32
v0.8.33
v0.8.34
v0.8.35
v0.8.36
v0.8.37
v0.8.38
v0.8.39
v0.8.40
v0.8.41
v0.8.42
v0.8.43
v0.8.44
v0.9.0
v0.9.1
v0.9.10
v0.9.100
v0.9.101
v0.9.11
v0.9.12
v0.9.13
v0.9.14
v0.9.15
v0.9.16
v0.9.17
v0.9.18
v0.9.19
v0.9.2
v0.9.20
v0.9.21
v0.9.22
v0.9.23
v0.9.24
v0.9.25
v0.9.26
v0.9.27
v0.9.28
v0.9.29
v0.9.3
v0.9.30
v0.9.31
v0.9.32
v0.9.33
v0.9.34
v0.9.35
v0.9.36
v0.9.37
v0.9.38
v0.9.39
v0.9.4
v0.9.40
v0.9.41
v0.9.42
v0.9.43
v0.9.44
v0.9.45
v0.9.48
v0.9.49
v0.9.5
v0.9.50
v0.9.51
v0.9.52
v0.9.54
v0.9.55
v0.9.59
v0.9.6
v0.9.60
v0.9.62
v0.9.63
v0.9.64
v0.9.65
v0.9.66
v0.9.67
v0.9.68
v0.9.69
v0.9.7
v0.9.70
v0.9.71
v0.9.72
v0.9.73
v0.9.74
v0.9.75
v0.9.76
v0.9.77
v0.9.8
v0.9.9
v0.9.98
v0.9.99

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66027.json"