The ConfigKeyCache uses the same cache key for both master key and read-only master key when resolving function-typed keys. Under specific timing conditions, a read-only user can receive the cached full master key, or a regular user can receive the cached read-only master key.
The fix uses distinct cache keys for master key and read-only master key.
Avoid using function-typed master keys, or remove the agent configuration block from your dashboard configuration.
{
"cwe_ids": [
"CWE-1289"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-25T19:00:07Z",
"nvd_published_at": "2026-02-25T03:16:05Z",
"severity": "HIGH"
}