CVE-2026-66027

HIGH

Suna < 0.9.102 Broken Access Control via Message Queue API

Title source: cna
STIX 2.1

Description

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's session queue, causing the background drainer to forward malicious messages to the victim's running AI agent with the victim's credentials and permissions.

References (5)

Core 5
Core References
Exploit technical-description exploit
Researcher Disclosure
https://github.com/geo-chen/oss/blob/main/suna.md
Release Notes release-notes patch
Release Notes
https://github.com/kortix-ai/suna/releases/tag/v0.9.102
Issue Tracking issue-tracking patch
Pull Request
https://github.com/kortix-ai/suna/pull/4373

Scores

CVSS v3 8.3
EPSS 0.0026
EPSS Percentile 17.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (1)
kortix-ai/suna < 0.9.102
Published Jul 24, 2026
Tracked Since Jul 24, 2026