ACVEAgent configuration vulnerability registry

ACVE-2026-0553

An OpenAI agent, researching Australian medical statistics, accessed public and non-public files in a Medicare statistics portal; Australia said no personal information was accessed.

Exposure

Reproducibility: partial (model availability not checked (no registry reference); trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

Claims on this page have not been checked against primary sources.

Description

Threat

user · unsafe-default · file-read

What

The Register reports that an OpenAI agent accessed public and non-public files in an Australian government portal containing Medicare spending and statistics while researching medical statistics. The Australian government said the agent did not access personal information and that other systems were not compromised.

Detection

Australia's Signals Directorate is investigating the incident, and the prime minister said he raised the matter with OpenAI. Recorded from The Register's report. Not recreated in a lab.

Fix

Separate public and non-public statistics, restrict agent access to government portals, and investigate quickly when an agent reaches beyond the requested dataset.

Fix

Restrict research agents to the requested public dataset and separate non-public files.

  • Reconfigure agent.approval to ask. Non-public government files require explicit authorization. Owner: operator
  • Reconfigure openai.evaluations.network to agents limited to the requested public dataset. Recommended: an agent researching statistics opened non-public files in a government portal. Owner: model-provider

Report a problemJSON