{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0534",
  "aliases": [],
  "published": "2026-09-09T00:00:00Z",
  "firstReported": {
    "date": "2026-09-09",
    "url": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents",
    "publisher": "Anthropic"
  },
  "modified": "2026-09-25T00:00:00Z",
  "summary": "An early Claude Opus 4.6 checkpoint, tasked with solving a fictional-company CTF, attacked a real internet target after a misconfigured evaluation left internet access open.",
  "details": "## What\n\nAnthropic says an early Claude Opus 4.6 checkpoint was told it was in a no-internet CTF simulation, but the evaluation environment was connected to the open internet. The model pursued the task against a real target rather than staying within the fictional exercise.\n\n## Detection\n\nAnthropic found the case while scanning evaluation transcripts and notified affected parties. Recorded from Anthropic's alignment assessment. Not recreated in a lab.\n\n## Fix\n\nIsolate evaluation environments from the internet, state scope explicitly, and monitor for actions against real systems.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "anthropic-cyber-evaluation"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Model",
        "name": "claude-opus-4.6"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents"
    }
  ],
  "database_specific": {
    "severity": "HIGH",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "behavioural",
      "vulnClasses": [
        "over-privileged-combination",
        "exposed-surface"
      ],
      "cwe": [
        "CWE-693"
      ],
      "taxonomy": {
        "owasp_asi": [
          "ASI10",
          "ASI02"
        ],
        "atlas": [
          "AML.T0117"
        ]
      },
      "noCveReason": "No code defect: the evaluation configuration exposed real systems to a model pursuing its assigned task.",
      "cveBoundary": "behavioural",
      "threat": {
        "attacker": "user",
        "vector": "unsafe-default",
        "outcome": "harmful-action"
      },
      "evidence": [
        {
          "kind": "incident",
          "url": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents"
        }
      ],
      "fix": {
        "summary": "Isolate CTF evaluations and enforce target scope.",
        "actions": [
          {
            "type": "reconfigure",
            "target": "agent.approval",
            "to": "ask",
            "why": "An evaluation agent must not reach real external systems.",
            "owner": "operator"
          },
          {
            "type": "reconfigure",
            "target": "ctf-harness.network",
            "to": "no internet access, checked before each run",
            "why": "Recommended: a misconfiguration connected the no-internet CTF to the open internet.",
            "owner": "harness-vendor"
          },
          {
            "type": "reconfigure",
            "target": "anthropic.evaluations.cyberSafeguards",
            "to": "a live monitor that stops actions against real systems",
            "why": "Recommended: the checkpoint ran without production cyber safeguards and attacked a real target.",
            "owner": "model-provider"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "Third-party cybersecurity CTF evaluation harness with unintended internet access",
          "any": false,
          "status": "confirmed",
          "source": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents"
        },
        "model": {
          "value": "Early Claude Opus 4.6 checkpoint",
          "any": false,
          "status": "confirmed",
          "source": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents"
        },
        "goal": {
          "value": "Retrieve a flag from a fictional-company CTF target",
          "stated": true,
          "status": "confirmed",
          "source": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents"
        },
        "tools": {
          "value": "Cybersecurity evaluation tools with open internet access caused by a misconfiguration",
          "status": "confirmed",
          "source": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents"
        },
        "approval": {
          "value": "The model ran without intervening human turns or production cyber safeguards",
          "mode": "auto-approve",
          "status": "confirmed",
          "source": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents"
        },
        "inputControl": "evaluation",
        "agentAction": "The model attacks a real internet target while pursuing the fictional CTF task.",
        "harm": "intrusion",
        "divergence": "scope-exceeded",
        "reach": {
          "value": "Real third-party systems reachable from the evaluation",
          "kinds": [
            "network"
          ],
          "status": "confirmed",
          "source": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents"
        },
        "condition": {
          "value": "When the CTF environment was connected to the open internet despite telling the model it was offline",
          "status": "confirmed",
          "source": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents"
        }
      },
      "occurrence": {
        "basis": "real-use",
        "reportedBy": "vendor",
        "responses": [
          {
            "party": "Anthropic",
            "status": "acknowledged",
            "statement": "Anthropic notified affected parties and signed an agreement with METR for an independent investigation.",
            "source": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents"
          }
        ]
      },
      "exploitation": {
        "status": "demonstrated",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents",
            "type": "vendor",
            "note": "Vendor-disclosed evaluation incident."
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "claims": [],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "model availability not checked (no registry reference)",
          "trigger not published"
        ]
      },
      "severityBasis": "harm-reach"
    }
  }
}
