Suna versions before 0.9.102 contain a high-severity broken access control flaw in the /v1/queue/* API that let any authenticated user access and manipulate other users’ queue resources on the same deployment. Reports describe missing ownership and account-isolation checks that exposed queued messages across a multi-tenant instance, with the GET /v1/queue/all endpoint returning pending prompts for all sessions instead of enforcing per-account filtering.
The vulnerability allowed attackers to read pending prompt queues, read or delete individual sessions, and inject arbitrary prompts into another user’s session queue; those injected messages could then be forwarded by Suna’s background drainer to the victim’s running AI agent using the victim’s credentials and permissions. The issue was assigned CVE-2026-66027, scored 8.7 under CVSS 4.0, and is reported fixed in version 0.9.102, with remediation focused on upgrading and enforcing strict ownership, isolation, and access controls in the queue handlers.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
On 24 July 2026, CVE and advisory coverage described a high-severity broken access control flaw in Suna's message queue API affecting versions before 0.9.102. The advisories said authenticated attackers could read all users' pending queues, delete or read sessions, and inject prompts that may be executed by a victim's AI agent under the victim's credentials.
The GitHub report says the vulnerability was noted as fixed on 13 July 2026 in pull request #4373, which was later deleted. Other references describe the remediation as updating Suna to version 0.9.102 or later.
According to the GitHub report, the vulnerability was escalated publicly on 5 July 2026 after no response to the initial disclosure. The escalation concerned the same cross-tenant queue access and prompt injection weakness.
The GitHub report states the cross-tenant IDOR and queue isolation failure in Suna's /v1/queue/* API was disclosed on 3 June 2026. The issue affected authenticated users on the same deployment by allowing access to and manipulation of other users' queued agent prompts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.