CVE-2026-66027
HIGHSuna < 0.9.102 Broken Access Control via Message Queue API
Title source: cnaDescription
Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's session queue, causing the background drainer to forward malicious messages to the victim's running AI agent with the victim's credentials and permissions.
References (5)
Core 5
Core References
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/suna-broken-access-control-via-message-queue-api
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/geo-chen/oss/blob/main/suna.md
Release Notes release-notes
patch
Release Notes
https://github.com/kortix-ai/suna/releases/tag/v0.9.102
Patch patch
Patch Commit
https://github.com/kortix-ai/suna/commit/7536a7d47fc93abcb66e677fcc993b390c81296a
Scores
CVSS v3
8.3
EPSS
0.0026
EPSS Percentile
17.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-862
Status
published
Products (1)
kortix-ai/suna
< 0.9.102
Published
Jul 24, 2026
Tracked Since
Jul 24, 2026