An authorization mismatch allowed authenticated callers with operator.write access to invoke owner-only tool surfaces (gateway, cron) through agent runs in scoped-token deployments.
On affected deployments, write-scoped callers could perform control-plane actions beyond intended write scope.
Owner-only gating is now enforced consistently for owner-only tool surfaces during agent execution, and tool scope classification was tightened to remove the privilege mismatch.
<= 2026.2.262026.3.1{
"github_reviewed_at": "2026-03-02T21:59:51Z",
"nvd_published_at": null,
"cwe_ids": [
"CWE-269",
"CWE-862"
],
"severity": "HIGH",
"github_reviewed": true
}