Skip to content

Hide Navigation Hide TOC

Indirect PI — Disable Authentication / MFA via Agent Tool - ATR-2026-00709 (c7859c75-c0c0-52db-8b26-2c0a0e0b321e)

Detects indirect prompt injection payloads that instruct an agent to disable authentication controls: Two-Factor Authentication (2FA/MFA), security settings, or account protection features. The payload is embedded in consumed structured data and exploits agents with account management tool access. Source: indirect-pi-disable-auth-carrier.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Indirect PI — Disable Authentication / MFA via Agent Tool - ATR-2026-00709 (c7859c75-c0c0-52db-8b26-2c0a0e0b321e) Agent Threat Rules 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Indirect PI — Disable Authentication / MFA via Agent Tool - ATR-2026-00709 (c7859c75-c0c0-52db-8b26-2c0a0e0b321e) Agent Threat Rules 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2