CVE-2026-46354
published 2026-07-07CVE-2026-46354: Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and…
PriorityP264critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.32%
22.0th percentile
Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, `azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. `{"vmId":""}` and the forged `vmId` will be accepted returning the victim workspace agent's session token. No authentication is required. The attacker only needs to know a target VM's `vmId` which is a `UUIDv4`. That's a practical limitation which would typically require prior access to be exploited. Versions 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, reconfigure any Azure templates to use token authentication rather than `azure-instance-identity`.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coder | coder | < 2.24.5 | 2.24.5 |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | >= 2.29.0 < 2.29.13 | 2.29.13 |
| coder | coder | >= 2.30.0 < 2.30.8 | 2.30.8 |
| coder | coder | >= 2.31.0 < 2.31.12 | 2.31.12 |
| coder | coder | >= 2.32.0 < 2.32.2 | 2.32.2 |
| coder | coder | >= 2.33.0 < 2.33.3 | 2.33.3 |
| github.com | coder_coder | 0 – 0.27.3 | — |
| github.com | coder_coder_v2 | >= 0 < 2.24.5 | 2.24.5 |
| github.com | coder_coder_v2 | >= 2.29.0 < 2.29.13 | 2.29.13 |
| github.com | coder_coder_v2 | >= 2.30.0 < 2.30.8 | 2.30.8 |
| github.com | coder_coder_v2 | >= 2.31.0 < 2.31.12 | 2.31.12 |
| github.com | coder_coder_v2 | >= 2.32.0-rc.0 < 2.32.2 | 2.32.2 |
| github.com | coder_coder_v2 | >= 2.33.0-rc.0 < 2.33.3 | 2.33.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Coder up to 2.33.2 Azure Identity azureidentity.Validate vmId certificate validation
vuldb·2026-07-07·CVSS 9.1
CVE-2026-46354 [CRITICAL] Coder up to 2.33.2 Azure Identity azureidentity.Validate vmId certificate validation
A vulnerability was found in Coder up to 2.33.2. It has been declared as problematic. This impacts the function azureidentity.Validate of the component Azure Identity. The manipulation of the argument vmId results in improper certificate validation.
This vulnerability is cataloged as CVE-2026-46354. The attack may be launched remotely. There is no exploit available.
GHSA
Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
ghsa·2026-05-19
CVE-2026-46354 [CRITICAL] CWE-347 Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
## Summary
`azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. `{"vmId":""}` and the forged `vmId` will be accepted returning the victim workspace agent's session token.
**No authentication is required.** The attacker only needs to know a target VM's `vmId` which is a `UUIDv4`.
> that's a practical limitation which would typically require prior access to be exploited
## Root Cause
In unpatched Coder releases the signature over the PKCS#7 content is not validated - only the signing certificate is checked.
##
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/coder/coder/pull/25286https://github.com/coder/coder/releases/tag/v2.24.5https://github.com/coder/coder/releases/tag/v2.29.13https://github.com/coder/coder/releases/tag/v2.30.8https://github.com/coder/coder/releases/tag/v2.31.12https://github.com/coder/coder/releases/tag/v2.32.2https://github.com/coder/coder/releases/tag/v2.33.3https://github.com/coder/coder/security/advisories/GHSA-6x44-w3xg-hqqf
2026-07-07
Published