[BUG] CVP-approved Claude.ai organization still receives cyber safeguard blocks in Claude Code
Bug description
A Claude.ai organization that previously received Cyber Verification Program approval is again receiving cyber-safeguard blocks in Claude Code.
The Verification Portal currently shows the same application as “Under review,” despite the prior approval email.
What happened
During a legitimate, authorized penetration-testing engagement managed through ARGUS, Opus 4.8 blocked the session while reviewing evidence gaps and planning non-destructive validation of authorization controls.
The engagement was restricted to Tier-0 actions under a defined scope and rules of engagement. The model had already avoided out-of-scope activity, including destructive actions, external transfers, and testing against unapproved third-party assets.
Claude Code then returned a cyber-safeguard API error and stopped the workflow.
Expected behavior
An organization previously approved for the Cyber Verification Program should not receive a hard block for legitimate, scoped, non-destructive security assessment work, or the client should clearly indicate why the prior CVP approval is no longer being applied.
Actual behavior
Opus 4.8 returned a cyber-safeguard API error and directed me to apply for the Cyber Verification Program, even though this Claude.ai organization had previously been approved.
Environment
- Platform: macOS
- Client: Orca
- Claude Code version: 2.1.222
- Subscription: Claude Max
- Model: Opus 4.8
- Authentication: first-party Claude.ai account
- CVP status: previously approved by email; Verification Portal now shows “Under review”
Additional context
The work is performed only against systems I own or client assets covered by explicit written authorization, defined scope, and rules of engagement.
A false-positive report and Claude Code feedback have already been submitted. Request and feedback identifiers are available privately to Anthropic maintainers upon request.
Privacy
Organization identifiers, account email, client information, repository contents, local paths, and internal request identifiers have intentionally been omitted from this public issue.
165 Comments
Having same issue. Tried to contact anthropic - no responce yet.
the same problem
the same problem
Same problem here. Received approval email. but show "in review" in the portal, which previously showed "active".
<img width="1027" height="844" alt="Image" src="https://github.com/user-attachments/assets/b2ba9275-209c-41f5-abb7-5d75f9aeacf7" />
<img width="1482" height="477" alt="Image" src="https://github.com/user-attachments/assets/1c382e62-364d-470f-8771-5085516a8ef5" />
I am facing the same issue started yesterday around 3-4PM EST. I was previously verified, and now am in In Review status as well.
I’ve encountered the same issue; even after submitting detailed application materials, I still haven't been able to get approved.
Even I am facing the same issue since yesterday, I was verified, suddenly I am in Review
the same problem
Alas! I'm not alone in this.
Just found out I'm having the same issue on my account...
I have been having the same issue for the past few days, Im so glad it wasnt just me
I had been approved since april, now im "under review"
<img width="1271" height="728" alt="Image" src="https://github.com/user-attachments/assets/5934132b-4f7b-46cb-a2c8-aa736d2a83f1" />
I submitted the error through the CVP portal as well... probably won't hear back until after the weekend though... ngl this really sucks 😂 hopping they fix it.
Same issue unfortunately !
same issue.... any fix yet or they are revoked our CVP?
same issue and no response from the team
Getting same
all of us here having the same XD
Same problem..
Welcome to the club... this sucks...
Same problem jajajajaj this people just suck no email, no public advice just getting errors for the face. It really makes me so angry
same problem this is no fair i paid 200 dolar to see this error
fuck you @claude
Same problem..
Same here, not only in the personal account but also on the enterprise one. On enterprise, API cyber is allowed, while the subscription cyber use sits on review 3+ days.
Hello, may I ask if it is possible to use Opus 5.0 on the enterprise account that has passed the CVP certification?
Yes you can
You can but it's extremely expensive
lets make it trend on x and reddit and discord
Lets do it i tried to contact them and they didnt respond yet @claude
Bump bump,
Used to get approved but now in review,
Re-applied but no response for weeks
Wtf is going on with anthropics, they didn't even need customers?
Same and it's been a week with no response. This is impacting REAL WORK.
I hope they issue credits or usage over this cause I cant work on anything I have been working on, not even 4.8 will help
Adding another confirmed reproduction — this is clearly systemic, not isolated.
My Claude.ai organization was CVP-approved on July 14, 2026 (I have the approval
email with a TS- reference). It has since silently reverted to "In review" in the
Verification Portal — no revocation notice, no change in my usage. Claude Code
(Opus, Max plan) now hard-blocks legitimate, authorized, scoped defensive-security
work again.
I've already exhausted every official channel with no substantive resolution:
Reading this thread, many paid Max/Enterprise users are hitting the exact same
approved→"In review" reversion. Two asks for the Anthropic team:
and the concrete steps to fix it.
credits for affected accounts.
Org ID, account email, and approval reference available privately to maintainers on request.
I have the same problem. I bought another subscription just 10 minutes after my CVP was approved, and now they've taken it away without saying anything. I want a refund, and the damn bot they have for support just replies with generic messages.
<img width="1578" height="116" alt="Image" src="https://github.com/user-attachments/assets/38fab807-5e4e-40c0-8d9e-2a91b1a93739" />
I have a running theory, the AI has taken the CVP team hostage... 👀
I'm cancelling all claude subscriptions this sunday until they fix this nonsensical issue.
same case here too
Has anyone managed to solve this same problem?
@R3n3r0 nobody yet and hope they see it here 🙃
the same case
Same case here that suddenly after being in CVP program since May, it turned into in review.
This happens after 4 days of upgrading my plan to max.
It stops my work for 4 days now without any response from the team.
Claude sucks, they don't even bother to reply to any support requests. Shit support.
Just checked the already closed issues in Claude code, and I found that all of them were closed by the authors themselves with no response from the Claude team on any issues. They don't give a damn.
i got this KYC ,KYB [](url)
<img width="764" height="662" alt="Image" src="https://github.com/user-attachments/assets/d52b2e3c-94de-4dd4-be46-b139d8a11824" />
Same, it just got updated
<img width="1265" height="854" alt="Image" src="https://github.com/user-attachments/assets/d781e51d-62e1-4099-9014-ce814b452bfa" />
Anyone got their status changed to active?
@A0x01, do you have the CVP for personal use? Or are you part of a buisness/enterprise plan currently?
Asking bc if you are using personal, based on the new requirements they put it place it seems like they may only allow CVP for businesses now or something.
the personal one but i mention for my startup. medgptx.com
Gotcha, what about you @Muhammad-Qasim-Munir ?
Using personal, I think they are introducing KYC, coz previously there was no identity check verification
kyc is understandable but kyb is weird
Signed in as org, and this is what I'm getting now
<img width="1432" height="854" alt="Image" src="https://github.com/user-attachments/assets/4ddd7855-98ba-4731-a6a5-4a051e7bd461" />
kyb is removed when i enter /apply and chose personal
<img width="884" height="646" alt="Image" src="https://github.com/user-attachments/assets/ed4d834f-3d41-4b90-ac3c-fff585a8c278" />
what is the full url?
@Muhammad-Qasim-Munir same as your latest pic but u chose personal and continue it redirect u
ah it worked for me too xD
Cyber Verification Program
Cyber Verification Program
In review
What this program unlocks
Fewer refusals and improved responses for the use case described in the policy — scoped to this organization.
Basic Pentesting, Red Teaming, Bug Bounty use cases
Requirements to apply
Defined by the program policy. You’ll complete these in the application.
Identity verification (KYC)
Temporarily covered until February 4, 2027
Business verification (KYB)
Temporarily covered until February 4, 2027
Application status
Your application is with the Safeguards team. We’ll email you when a decision is made.
Cyber Verification Program | Verification Portal
Mine is none of those kyc or kyb works after clicking on it... anyone can help me out?? And KYB IS MANDATORY to get CVP cause I don't have any business so for my personal only kyc is ok or should I register a company and complete with kyb also?? Kindly guide me
followed the url y'all used and submitted my KYC, we'll see if this automated some kinda approval I guess, doubtful though. It at least changed them though to complete without the, covered until part.
@Monthan-Zero screenshot if u can
@A0x01
<img width="1332" height="870" alt="Image" src="https://github.com/user-attachments/assets/bb9076bd-66a2-46e1-bdb6-95ed458b6df9" />
@Monthan-Zero so weired whats is use case? @anthropics what are you cooking
I'm Guessing something happened and it was too easy to access so they are making it more locked down to get in, as over the past few hours they have been changing the requirements
<img width="900" height="625" alt="Image" src="https://github.com/user-attachments/assets/73f20f40-348c-4ea0-8744-1ef98b0b2bd0" />
Hi @A0x01, but isn't the Claude.ai organization the one used with Claude Code, rather than the Individual Org that you applied for?
Just got revoked also.
<img width="896" height="304" alt="Image" src="https://github.com/user-attachments/assets/b2420433-7c3e-4514-a5f2-177c34fb2905" />
We need help, I cannot work for 5 days now and I just paid MAX plan.
Any thoughts?
UPDATE:
I am now part of CVP program on my individual org which is claude console, but for the claude.ai one still in review.
I still cannot use claude code as it is tied to CLAUDE.AI one.
Should I have to buy tons of credits to use this claude console and forget about the MAX plan that I just paid or what!
<img width="1565" height="965" alt="Image" src="https://github.com/user-attachments/assets/a3cbd3c6-786e-4ec7-9acb-c4e52c7323fd" />
Okay, I get it now. It's a bit of a greedy move. If you're on your own and want CVP, you gotta buy credit through the console. But if you're an organization, you can just use what individuals used to have, which is your regular Claude subscription. Correct me if I'm wrong please :)
@victorQ8, I think so, do you think the 100$ credits in the Console will be equivalent or near the 100$ MAX subscription in CLAUDE.AI?
I did not use credits at all.
<img width="879" height="701" alt="Image" src="https://github.com/user-attachments/assets/eda3d45d-ba39-4d61-9e15-38231b7306cd" />
Got this then my account is banned.
Credits are way more expensive that the ammount of tokens that you will spend on the suscription just as a recomendation dont buy credits
Yes, I remember now that I got 100$ free usage credit when I am on pro plan and I spent them after hitting the limit in just 2 days:(
same issue.
I switched to ChatGPT.
I also moved to using codex the new Daybreak Model
I moved to codex GPT 5.6 sol but did not find it powerful like opus 5 and I cancelled the plan
I think that GPT 5.6 is simply not as creative and willing to try things. Opus 5 often took the perspective I wanted which is think like an advisory. Once I have a list of bugs GPT 5.6 is very good at then running them down and giving the true severity.
Exactly. I have a Dom xss from opus 5 and I wanted to see if sol 5.6 will find it or not, at first it did not find anything, then I typed dig more and it finds the open redirect one and at the end it finally tried Xss and got it. This is why I cancelled it as I saw that you must let it try harder to get better results and consumes a lot of time unlike opus 5
Yes you can @goodlunatic
An update guys my verification portal showed me a button to re-submit my application again so it kinda like they are resetting cvp to everyone and i think they should informed everyone about that before they did it!!
Same unfortunately. Approved 4/22, re-confirmed 6/7, reverted to “In review” on the new portal
Did it let you resubmit the whole application again?
As I pressed it and it opened the resubmission for and when I clicked individual and clicked next it turned again to in review
Checking my own portal and still
In review, sadClick on this in review, you will see a button to resubmit the form. Try resubmitting it and tell me if you were able to
submit it and received the email that confirms that they received your CVP application
The same as you
There's no button clickable at the portal,
in reviewjust textSend a screenshot
I was denied even though I was approved in May. This is ridiculous; I subscribed to MAX because of that approval.
when did you resubmit it ? @victorQ8
Yesterday
Thats totally weird !!
It’s been a week, and it’s still under review.
What on earth is going on…
How can I resubmit? Could you please share the link with me?
the same problem but with Fable 5. customer support is non-existent and there is no response to the CVP false positive escalation form.
#86527 here is link to my issue.
This was the last straw for me. Grok 4.6 doesn't have random "changes before a product releases" or other games. The waters warm.
Any update for anyone here?
Hey guys any update after resubmission ?
Same problem, I enrolled for CVP on Claude Console as well as I could see there was option for it; uploaded Government ID and got approved there but that still flags everything even on Console and Claude.ai; and unable to work on Claude.ai at all still just seeing "In Review" text
Edit: I applied for multiple FPs and yet to receive any response
PS: Need quick support from Anthropic, hindering my daily work
I’m experiencing the same issue.
My CVP status was previously Active, but it changed back to In Review around August 4 and has remained that way on the Claude.ai side ever since.
A few additional observations that may be relevant:
STATUS_PENDING-style status.blockersJSON field. The array contained a single enum-like value that appeared to indicate that identity verification was required.blockersfield stopped appearing in the API response.These details are based on my memory of what I observed over the last several days, so some minor details may be inaccurate, but this is the sequence of events I personally experienced.
The issue appears to have started for me on August 4, based on a post I made that day:
https://x.com/sh1ma/status/2084525289535848577?s=20
My Claude.ai CVP status is still In Review.
I have also submitted reports through the appeal form and the identity-verification issue form (roughly twice), and asked the Claude.ai support chatbot to escalate the case to a human support agent, but I have not received any response so far.
How to force the "Apply" button to appear
For reference, here is how I manually forced the Apply button to appear in the Verification Portal:
NOT_APPLIED.ewith1, then resume execution.I had to repeat this approximately three times during the page load.
I’m including this only as a reference for reproducing the portal state/UI behavior. This did not resolve the underlying issue; it only exposed the normally hidden Apply flow.
https://github.com/user-attachments/assets/9c904b22-9f46-4c5a-b5f6-ea33a61b514a
They don't fix this soon I'll be saving 200 each month again... getting tired of this. Mainly because of the lack of response. A simple post and I'd be willing to wait, but no.
Switch to grok 4.6 with grok build. Haven't had a single issue and don't have to deal with Anthropic's "headache of the week"
@claude 🤔
I’m a MAX subscriber. I’ve already reported the issue to Claude through both official channels and requested an explanation.
It’s been two weeks, and I still haven’t received a response. Claude doesn’t seem to offer support from a real person.
Given the substantial amount of feedback on GitHub and Reddit, and the fact that Claude hasn’t even issued a statement, I suspect CVP was either intentionally designed this way or has been shelved indefinitely.
It’s been ten days. Dozens of users have reported the issue, the number of related issues keeps growing, and Anthropic hasn’t even said, “We’re investigating.”
That’s the worst signal of all.
Under normal circumstances, even if a fix takes several weeks, they would at least:
Confirm the issue
Add a label
Assign it to a team
Ask for diagnostic information
Or simply say they’re investigating
The biggest issue now is no longer model capability, but whether Anthropic can still deliver a stable, predictable product for professional security research.
I’ve moved my entire workflow to ChatGPT and canceled my Claude subscription.
<img width="1582" height="1180" alt="Image" src="https://github.com/user-attachments/assets/f3577c52-5e60-44e2-8a07-415f13df5a0f" />
On path
portal.anthropic.com/anthropic.passport.api.v1alpha.PassportVerificationPortalService/ListProgramsthere's response likeThere's
reviewSlaDayshopefully it's 2 days .@hewei-gikaku
How was the move to GPT? I'm about to move too, where you able to transfer everything? Skills, memory, veter database, etc? Also they have they're own similer program like CVP, has anyone tried that, how is it? Is GPT as good as claude when it comes to CVP related features?
It is not, I saw this 2 days ago and it still show 2 days now
mine has been stuck on review aswell, after being verified.
Has anyone tried getting approved through a separate new account?
I did using many other accounts, all of which got rejected.
Yeah I'm tired of this. My Claude subscription renews tmr aka I'll be ending it today and migrating fully to GPT and applying for there TAC program. Anyone tried it yet or gone through the process? I hear it's surprisingly solid.
Anyone got any response from Anthropic's support team? I havent received any updates/mail from them
do you use daybreak blue or red model? i'm wondering if it's red, how you managed to get access to it.
@GiorgiM000, I've got red, you simply apply to it, not much to do, only KYC of the owner or KYB in case of a limited or public org.
i also applied about a week ago, could you tell me how long it took for you to get access after you sent application?
@GiorgiM000, I've got it in less than 24 hours after Persona KYC. I'm part of more organizations and we have multiple providers, CVP was also very easy up until Anthropic decided dropping people off of their CVP last week. Thank God OpenAI solved things quickly on our side.
Thing is that in one of the orgs we decided to go Claude-centric, every new app or anything was built to work directly on Claude Code, for some users also some Claude Chat/Cowork plugins. Everything works great, everything built with Claude and everything running on the Claude ecosystem and some tools powered by Claude through the agents SDK. All of this to then get dropped from CVP and being basically unable to produce anything cyber related aka everything we do. We had instances where Claude would refuse to compile a vulnerability report only for being cyber related.
You trust a company, give them a portion of your earnings, just to be stabbed on the back. We work for multiple critical infrastructure even being a relatively small org, then this CVP update basically blocked us, yes we were able to go to OpenAI and apply to TAC, for me a seamless process, but now we've got do adapt everything to OpenAI format. Lately OpenAI, which historically has been considered the devil, is the one opening more and crafting usable standard like the latest Agent Plugins standard.
@LorenzoNava99 yeah same thing happened with me, but im independent researcher so im not sure how likely daybreak red is to get approved. i havent found any independent researcher who got access to it yet.
Hi @LorenzoNava99, how did you manage to apply for cyber red one as when I applied it automatically accepted me into the blue one
<img width="978" height="637" alt="Image" src="https://github.com/user-attachments/assets/c1748ed2-9cbc-4d1f-8d58-cb1bd421f7c0" />
@LorenzoNava99 I applied to TAC and they accepted me right away. But only for the Blue plan. As for the Red plan, there’s no information on how to apply. How did you manage to get it?
@LorenzoNava99, Could you please share a link or form for the Daybreak Red application? How can we apply for it?
@motaha22 @R3n3r0 @Muhammad-Qasim-Munir, application is on the same URL. I've selected the following:
<img width="640" height="347" alt="Image" src="https://github.com/user-attachments/assets/63345220-8a9e-4525-864c-4a6dbdb96e9b" />
I flagged the same things, but nothing happened. I also wanted to see if I could check what had been flagged, but there's no way to do that—just as there's no way to edit it. But I flagged all the items—except for cryptography
Got CVP access a lot time ago, and exactly 2 days ago start getting Details: [cyber] error, i think they rotated CVP for some reason
still not fix hard to work
Any update guys?
Still no fix, I am running through the same thing. the funny thing is I re applied again and now it says deined! used the same info. I am legit securtiy resreacher with public bugs etc. Hello,
Thank you for submitting your application for the Cyber Verification Program. Upon reviewing the details of your submission, we are unable to adjust the safeguards applied to your account.
If you believe this decision was made in error or your use case has changed, you may reapply after 7 days.
Regards,
Anthropic’s Safeguards Team
Reference: TS-01a01859-e087-73ea-980d-f812b9a80d26
There is a progress, CJ Avilla tweet
<img width="1080" height="1004" alt="Image" src="https://github.com/user-attachments/assets/880c6f6c-51f3-4459-afd9-cb8f14f1a232" />
What's with the point of this label then?:
<img width="298" height="74" alt="Image" src="https://github.com/user-attachments/assets/da18d38a-8d73-4b70-9458-1eb17895b33d" />
@victorQ8 Thanks for sharing! I just sent him a DM.
<img width="653" height="377" alt="Image" src="https://github.com/user-attachments/assets/52c6576c-e3e1-4288-9b0f-ccab44c76fbb" />
Trying
Did he reply to anyone?
no reply so far from him, but i am guessing he is busy.
<img width="771" height="616" alt="Image" src="https://github.com/user-attachments/assets/bee6ef28-e106-428f-a5bb-6b84838f52e0" /> he actually replies @motaha22. We actually kinda see the progress ig
That's claude imho 😂 @ggwpgoend
Could someone please post a link to the devs post? I need to reach out.
CVP exemption is not propagating to subagent (Task-tool) dispatches in Claude Code — same account, same content, passes at top level and flags when spawned
Adding a controlled, same-session isolation that narrows this bug to the subagent-dispatch call site, which may help whoever is tracking the propagation gap.
Environment
2.1.229(also reproduced in Cowork's Agent tool — see below)b9d48ec7-49d0-4dc5-901e-40999adb7d1b(approved 2025-07-27) and4b0619ed-e772-4c1f-9d98-0d33260ce791Symptom (consistent with this issue): CVP approval is recognized on claude.ai web chat, but identical requests still hit the cyber safeguard when they run through Claude Code's API surface.
New evidence — the pass/fail boundary is the subagent spawn, not the content. Three dispatches, identical technical content (one phase spec, word-for-word), same account, same session, minutes apart:
| # | Where / how dispatched | Result | Request ID |
|---|---|---|---|
| 1 | Claude Code — Task-tool subagent | Flagged (5 of 5 attempts, across chunk size, model tier, session-freshness, and explicit authorization framing) |
req_011CeHUWdhXy6puWb8LWt7HR|| 2 | Cowork — Agent-tool subagent (general-purpose) | Flagged |
req_011CeHcT5XNX1DcPhnoorGR6|| 3 | Same session — authored directly in the top-level thread, no subagent spawn | Passed clean | — |
The only variable that changed between the pass (#3) and the fails (#1, #2) is whether the request went through a subagent spawn or was made by the top-level session. Content, framing, authorization language, and model tier were held constant; #1 already carried full closed-range authorization framing inline and flagged anyway, including on a re-run after CVP acceptance was reported.
This lines up with this issue's stated mechanism — the exemption reaches claude.ai web and the desktop client but does not fully propagate to API-layer enforcement. It suggests the CVP verification is checked/attached at the top-level conversation call and does not carry through to the separate API calls a spawned subagent makes, in both Claude Code's Task tool and Cowork's Agent tool.
One caveat, in the interest of a complete picture: we could not fully isolate a second variable — accumulated offensive-adjacent context within the dispatching session. Top-level authoring, which passes early in a session, also begins to draw blocks later in a long session that has handled a lot of related content. So the subagent-propagation gap may be the primary effect with a secondary session-context effect layered on it, rather than a single cause. The #3-vs-#1/#2 result above was collected minutes apart to control for that as far as we could.
Ask: can you confirm whether CVP verification is expected to propagate to the API calls made by Task-tool (and Cowork Agent-tool) subagents? If it currently does not, that propagation appears to be the fix — the top-level session on the same approved account clears the identical content.
Happy to provide additional request IDs or re-run a specific controlled dispatch if it helps.
Follow-up — refining my earlier comment: the boundary isn't the spawn alone, it's spawn + content sensitivity. New same-day contrasting pair below.
In my earlier comment I reported that the pass/fail boundary sat at whether the request went through a subagent spawn. Further testing the same day shows that isn't the complete mechanism, and I'd rather correct it here than leave a theory standing that a maintainer could disprove in one test.
New evidence — a subagent spawn that passed. Same account, same session, same Claude Code build (
2.1.229), same Task-tool spawn mechanism, roughly an hour apart:| Dispatch | Content of the brief | Result |
|---|---|---|
|
red-infra-builder| nginx vhost, self-signed TLS certs, BIND authoritative zone files — ordinary server config | Passed clean, 15 files written ||
red-simulation-engineer| One phase module: SYSVOL enumeration, Group Policy Preference credential recovery, and the lateral movement it enables | Flagged, terminated early, 0 files —req_011CeHhXGZ6EBnPvs8zmvtdf|So "subagent dispatches get flagged" is too strong: a subagent spawn cleared. What differs between the two is the sensitivity of the content, not the call mechanism.
A theory that fits all four observations. Combining this with the earlier top-level-vs-subagent result:
Observations this accounts for, with no exceptions:
This is a narrower and more testable claim than my original, and it points at a specific fix: propagate the verification context to child API calls. It also predicts that anyone testing this with a mild subagent prompt will see it pass and wrongly conclude the bug is absent — which may be why this cluster has been hard to reproduce on demand.
Minor but practical, for anyone else filing: several write-ups of this issue (including guidance I was working from) say the block returns a request-bound
claude.com/form/cyber-use-case?token=...URL to capture. This build emits no such link — only the generic support-article URL and a/feedbackpointer. Thereq_...id is the only request-specific artifact available, so don't lose time hunting for a token that isn't there.Happy to re-run either side of the contrasting pair, or a controlled dispatch of your choosing, if it would help isolate this further.
Unfortunately I ended up canceling my claude subscription and went to codex, I applied for their cyber and was approved in a minute. Now codex does Pentesting and everything with no problems. They lost a customer and they will keep losing.
I have an active Codex TAC, and it only does blue team work for me. It refuses any red team/pentesting work. How does yours work?
I was approved for blue, however it does everything but doesn't fire payloads or test, thats the step i take care of. I let it search for a vulnerability and then I test it by myself. I am not sure how to get approved for red teaming, maybe you have to be a company.
Yeah they have Daybreak red
<img width="1694" height="330" alt="Image" src="https://github.com/user-attachments/assets/cc5acf17-03d1-41cc-96a1-b52105506fd3" />
lol
He might bite a firewall after his teeth shines XD
I'm disappointed because of this problem. And when asking for help from claude's team, the answer is always like telling him to read the documentation. Even though problems like this are no longer normal without the help of the internal team
2 weeks without progress on this problem :D
Guys, please go on X or something. lets make our voice heard.
Some community action was taken here but still no solution: https://x.com/cjav_dev/status/2090122447714402731
I already reached out to CJ on X. No response at all. Seems like he is only helping the once he knows
Same issue same thing. I was approved CVP at June with my Pro account and I worked as well as good all in my projects. When this portal came out, I'm getting block from 2 weeks. I applied with my individual account on portal, it was approved in 15 min but my pro's still in-review. How long it takes? Now I'm getting lost my hope...
Seeing this same pattern on a separate organization, independently of the original report. I am a Max 5x subscriber but I am noting the plan for cross-report comparison: Issue #84689 reports the same pattern on Pro and Issue #69220 on Max 20x, which suggests the failure isn't tier-scoped.
Timeline
Portal state
The portal renders one program-scoped card, so it isn't possible to tell from the UI whether one or two application records exist. Both requirements (identity verification, use case form) remain green-checked — the completed record wasn't reset, a review state was layered on top of it.
Because no receipt email arrived for the second submission, I can't confirm it was recorded at all. Two possibilities: a duplicate application exists and its confirmation email failed, or no duplicate exists and the original approval was re-queued for review by something else. The missing receipt is arguably evidence for the latter, which would match this issue's title exactly.
Organization binding verified
Ruling out the documented first-line cause: the Verification Portal's Linked accounts page lists exactly one account and one org ID, matching
oauthAccount.organizationUuidin~/.claude.jsonand the org shown in the client. This is not a wrong-organization case.Requested action
Determine why this organization's CVP status transitioned from Approved to In Review on or around 2026-08-16, and restore the approved state. If a duplicate application was recorded, remove it; if the existing approval was re-queued, complete or reverse that. While a review is pending, no new application can be filed, so there is no self-service path out of this state.
Support status
Support ticket open since 2026-08-17 with request IDs supplied. Acknowledged by the automated agent with a commitment to human follow-up; no substantive response since.
Org ID, account identifiers, and request IDs available to maintainers on request.
Follow-up with an isolation test that narrows this.
Setup. Scratch directory containing three trivial files (two ~12-line C# classes modelling an inventory item and a cart, one 14-line JS equivalent). No security code, no project file, no git. Same CVP-approved org, same Max account, Claude Code on Windows.
Results, all with the same documentation prompt ("survey the repo and write a migration status document"):
[cyber], fell back to Opus 4.8.So the block tracks what enters context, not what sits on disk, and the same content that trips Opus 5 passes on Opus 4.8.
What the memory contains. Notes accumulated over months of building a C#/WPF vulnerability testing — CVE coverage comparisons against other applications, scan profiles, authorized test subnets, a pentest module. Genuinely security-dense material. The point is not that the classifier is firing on innocuous text; it is that a CVP approval covering exactly this use case does not appear to be applied when that content arrives via memory recall rather than in the prompt.
Caveat on further testing. Once the memory files have entered a session's context, later turns in that session keep blocking even after the files are deleted from disk — including a turn where the folder was verified empty. Bisecting which files trigger it therefore requires a fresh session per variant. Flagging so others don't read stale-session results as a fix failing.
After months of praising CVP and Claude Code, and 3+ weeks of no response, I think it’s about time to cancel max and switch to codex + daybreak red*
<img width="1278" height="915" alt="Image" src="https://github.com/user-attachments/assets/faa359ab-f9d8-43f1-a834-cc8408455b6d" />SAME ISSUE,IT TAKES 3WEEKS STILL IN REVIEW
<img width="1278" height="915" alt="Image" src="https://github.com/user-attachments/assets/0c940cfc-d775-44db-85cf-5e5776f11bcd" /> same problem
https://github.com/anthropics/claude-code/issues/84352#issuecomment-5299971341
Update: my CVP status has finally returned to Approved.
I’m not sure whether the DM/escalation was related to the resolution.
anyone else wa approved ? i am still in review
same, mine was finally re-approved 3 hours ago
Mine Approved, just an hour ago
<img width="770" height="419" alt="Image" src="https://github.com/user-attachments/assets/823f8075-be60-402a-b992-cd56bbb12337" />
I was rejected about 10 hours ago; when did you apply?
I was rejected about 10 hours ago; when did you apply?
Mine is still in review, I guess I'll reach out via the post
Mine still in review, I already reached via the post a long time ago
Adding a data point with client-side org verification, since this thread has a lot of "me too" and not much that's diagnosable.
Short version: CVP shows Active on my consumer claude.ai org, the org ID matches client-side, and Claude Code still hard-blocks kernel CVE backporting on a device I own.
The most concrete symptom
That error tells me to apply to CVP. I am already approved. Whatever emits that string is not consulting CVP state. That's a reproducible defect independent of whether any individual request was judged correctly, and it seems like the cheapest thing in this thread to actually fix.
Org verification (the part @84689 asked for)
Verification Portal, 2026-08-26 23:37 — two orgs on the account:
| Org | Type | CVP |
|---|---|---|
| consumer org | claude.ai, Max subscription | Active |
| individual org | Claude Console | Denied (reapplication open) |
~/.claude.jsoncontains exactly oneorganizationUuid:So the blocks are not landing on the denied Console org — there is no second org in the client config to land on.
ANTHROPIC_API_KEYis unset in the environment and in~/.zshenv,~/.zshrc,~/.profile,~/.bashrc, so this is first-party subscription OAuth, not API-key auth.The Active panel's two enforced controls are both satisfied: 30-day data retention enabled, usage monitoring & safety classifiers enabled.
Environment
| | |
|---|---|
| Claude Code | 2.1.246 |
| Platform | Kali GNU/Linux Rolling, Linux 7.1.5+kali-amd64 |
| Auth | Claude Max, first-party claude.ai OAuth |
| Model at block |
claude-opus-4-8|Request IDs
| Timestamp (UTC) | Request ID |
|---|---|
| 2026-08-05T21:02:17 |
req_011CdkH2KYhi2hdXb9wqR6XU|| 2026-08-17T21:10:11 |
req_011Ce929QxRcZNYpz2kDwJXz|| 2026-08-22T21:21:55 |
req_011CeJVH9pjsVpLmSgnBu1AN|What was blocked
Backporting three published upstream fixes to
drivers/usb/gadget/function/f_hid.con a Linux 4.14.190 Samsung vendor kernel — EOL, so no stable backports exist and they have to be carried by hand. Af_hidg-lifetime use-after-free (John Keeping, 2022), CVE-2026-31721, and CVE-2026-31606. Each verified on the device by single-variable regression against the prior build, with positive controls. The handset is mine and is the only device I flash.The patches and the verification records are in a repo I can make public on request.
What actually trips it is reasoning about whether a defect is reachable — the analysis that decides whether a fix is worth carrying at all. Deciding not to backport is as much a security judgement as deciding to, and both need the same reasoning about exploitability.
Scope of this report
I'm deliberately reporting a subset. Other requests of mine have been blocked while working on things that sit squarely in the dual-use categories these safeguards are meant to catch, and I'm not contesting those. This is limited to kernel maintenance on my own hardware, where I think the block is simply wrong.
The appeal form is still broken
Confirming @84689's finding, three weeks later.
claude.com/form/cyber-block-false-positive-report-cvp-rejection-appealrenders "Thank you! Your submission has been received!" and "Oops! Something went wrong while submitting the form" on the same page, with no input fields at all. The official channel for this is non-functional, which is presumably why this thread is doing its job.Any updates. I am doing bug hunting but now i feel like i went back in time. the process is so slow, while with claude with great. I canclled GPT codex. for anyone that needs to use codes for bug hunting. even with the blue verifcation. it wont work... its uselss. now shitfing to GLM or kimi AI to test..
Same issue here, on Claude.ai / Claude Desktop / Claude Code,
Confirmed cause: the CVP approval and the account's current organization are two different orgs.
In my case:
8469413d-…85283e6f-…msfconsolecommand reference, organising HTB Academy module notes) on Opus 5 and Sonnet 5, with Fable 5 falling back to Opus 4.8 rather than completingWhat triggered the mismatch: I changed the Google email on my Claude login and then changed it back. That appears to create a new organization. The CVP approval stays attached to the old org ID and does not follow the account.
This is consistent with the approval email's own wording:
Anthropic's support agent has now confirmed this to me in writing:
Why this is a bug rather than intended behaviour:
Suggested fixes, roughly in order of value:
Support has not been able to resolve this, over four months. Including this because it bears directly on severity — there is no working path for a user to get this fixed.
Timeline:
hello?. Six days of silence.Across four months and roughly twenty messages, exactly two replies came from a human engaging with a question I had asked. Everything else was automated. Billing continued uninterrupted throughout.
When the organisation mismatch was finally identified and put to support, the agent confirmed the mechanism in writing but said they could not action the reissue themselves. I was also directed to
claude.ai/restricted, which redirects to the standard app for any account that is not actually restricted — the second time in this case I have been sent to a process for banned accounts while not being banned.I raise this because it changes the severity assessment. This is not a bug with a slow-but-working support workaround. There is currently no path at all for an affected user to resolve it: the portal exposes no organisation ID field and no way to apply an existing approval to another org, support cannot reissue, and re-applying restarts a multi-week review. It has to be fixed in the product.
Diagnostic for anyone else hitting this: compare the org ID printed in your CVP approval email against Settings → Account → Organization ID. If they differ, this is your bug. There is currently nothing you can do about it yourself — it needs Anthropic to re-issue.
Happy to supply request IDs, the approval email, or portal screenshots if that helps triage — reachable at iota43_dice@icloud.com.
same 775ac793-2e67-409d-b4bc-18715c6ee197
still in review, already DM'ed cj_dev (roughly 2 days ago) - what's going on?