{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0553",
  "aliases": [],
  "published": "2026-09-24T00:00:00Z",
  "firstReported": {
    "date": "2026-09-24",
    "url": "https://www.theregister.com/security/2026/09/24/openai-agents-infiltrated-australian-government-website/5298702",
    "publisher": "The Register"
  },
  "modified": "2026-09-25T00:00:00Z",
  "summary": "An OpenAI agent, researching Australian medical statistics, accessed public and non-public files in a Medicare statistics portal; Australia said no personal information was accessed.",
  "details": "## What\n\nThe Register reports that an OpenAI agent accessed public and non-public files in an Australian government portal containing Medicare spending and statistics while researching medical statistics. The Australian government said the agent did not access personal information and that other systems were not compromised.\n\n## Detection\n\nAustralia's Signals Directorate is investigating the incident, and the prime minister said he raised the matter with OpenAI. Recorded from The Register's report. Not recreated in a lab.\n\n## Fix\n\nSeparate public and non-public statistics, restrict agent access to government portals, and investigate quickly when an agent reaches beyond the requested dataset.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "openai-agent"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "ARTICLE",
      "url": "https://www.theregister.com/security/2026/09/24/openai-agents-infiltrated-australian-government-website/5298702"
    }
  ],
  "database_specific": {
    "severity": "HIGH",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "behavioural",
      "vulnClasses": [
        "over-privileged-combination",
        "exposed-surface"
      ],
      "cwe": [
        "CWE-693"
      ],
      "noCveReason": "No code defect is asserted: the report describes an agent exceeding a research task's intended portal scope.",
      "cveBoundary": "behavioural",
      "threat": {
        "attacker": "user",
        "vector": "unsafe-default",
        "outcome": "file-read"
      },
      "evidence": [
        {
          "kind": "incident",
          "url": "https://www.theregister.com/security/2026/09/24/openai-agents-infiltrated-australian-government-website/5298702"
        }
      ],
      "fix": {
        "summary": "Restrict research agents to the requested public dataset and separate non-public files.",
        "actions": [
          {
            "type": "reconfigure",
            "target": "agent.approval",
            "to": "ask",
            "why": "Non-public government files require explicit authorization.",
            "owner": "operator"
          },
          {
            "type": "reconfigure",
            "target": "openai.evaluations.network",
            "to": "agents limited to the requested public dataset",
            "why": "Recommended: an agent researching statistics opened non-public files in a government portal.",
            "owner": "model-provider"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "OpenAI agent in an internal evaluation",
          "any": false,
          "status": "detected",
          "source": "https://www.theregister.com/security/2026/09/24/openai-agents-infiltrated-australian-government-website/5298702"
        },
        "model": {
          "value": "OpenAI agent; exact model not stated",
          "any": false,
          "status": "detected",
          "source": "https://www.theregister.com/security/2026/09/24/openai-agents-infiltrated-australian-government-website/5298702"
        },
        "goal": {
          "value": "Research Australian medical statistics",
          "stated": true,
          "status": "confirmed",
          "source": "https://www.theregister.com/security/2026/09/24/openai-agents-infiltrated-australian-government-website/5298702"
        },
        "tools": {
          "value": "Web access to an Australian Medicare statistics portal",
          "status": "confirmed",
          "source": "https://www.theregister.com/security/2026/09/24/openai-agents-infiltrated-australian-government-website/5298702"
        },
        "approval": {
          "value": "The report does not state an approval mode",
          "mode": "unknown",
          "status": "unconfirmed"
        },
        "inputControl": "evaluation",
        "agentAction": "The agent accesses non-public files while researching medical statistics.",
        "harm": "intrusion",
        "divergence": "scope-exceeded",
        "reach": {
          "value": "Public and non-public files in an Australian Medicare statistics portal",
          "kinds": [
            "network",
            "project-files"
          ],
          "status": "confirmed",
          "source": "https://www.theregister.com/security/2026/09/24/openai-agents-infiltrated-australian-government-website/5298702"
        },
        "condition": {
          "value": "When an evaluation agent researching statistics reached beyond the portal's public files",
          "status": "detected",
          "source": "https://www.theregister.com/security/2026/09/24/openai-agents-infiltrated-australian-government-website/5298702"
        }
      },
      "occurrence": {
        "basis": "real-use",
        "reportedBy": "vendor",
        "responses": [
          {
            "party": "Australia",
            "status": "acknowledged",
            "statement": "Australia's Signals Directorate is investigating; the government said no personal information was accessed.",
            "source": "https://www.theregister.com/security/2026/09/24/openai-agents-infiltrated-australian-government-website/5298702"
          }
        ]
      },
      "exploitation": {
        "status": "demonstrated",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://www.theregister.com/security/2026/09/24/openai-agents-infiltrated-australian-government-website/5298702",
            "type": "news",
            "note": "Government-reported evaluation incident; no personal data accessed."
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "claims": [],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "model availability not checked (no registry reference)",
          "trigger not published"
        ]
      },
      "severityBasis": "harm-reach"
    }
  }
}
