CVE-2026-55429
published 2026-07-08CVE-2026-55429: Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2…
PriorityP348high8.7CVSS 3.1
AVNACLPRHUINSCCHIHAN
EPSS
0.51%
42.4th percentile
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` accepts the app ID from the provisioner's `CompleteJob` payload without verifying it belongs to the workspace being built. `CompleteJob` runs under `dbauthz.AsProvisionerd` so the authorization layer does not block the cross-workspace upsert. Exploitation requires elevated access as a template author or external provisioner operator. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 verifies that any existing `workspace_apps` row matching the supplied ID belongs to the workspace being built and rejects cross-workspace agent reassignment. No known workarounds are available.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coder | coder | < 2.29.17 | 2.29.17 |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | >= 2.30.0 < 2.32.7 | 2.32.7 |
| coder | coder | >= 2.33.0 < 2.33.8 | 2.33.8 |
| coder | coder | >= 2.34.0 < 2.34.2 | 2.34.2 |
| github.com | coder_coder_v2 | >= 0 < 2.29.17 | 2.29.17 |
| github.com | coder_coder_v2 | >= 2.30.0 < 2.32.7 | 2.32.7 |
| github.com | coder_coder_v2 | >= 2.33.0 < 2.33.8 | 2.33.8 |
| github.com | coder_coder_v2 | >= 2.34.0 < 2.34.2 | 2.34.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Coder up to 2.29.6/2.32.6/2.33.7/2.34.1 Workspace App Provisioner UpsertWorkspaceApp/insertAgentApp app ID improper authorization
vuldb·2026-07-08·CVSS 8.7
CVE-2026-55429 [HIGH] Coder up to 2.29.6/2.32.6/2.33.7/2.34.1 Workspace App Provisioner UpsertWorkspaceApp/insertAgentApp app ID improper authorization
A vulnerability classified as problematic was found in Coder up to 2.29.6/2.32.6/2.33.7/2.34.1. Affected by this issue is the function UpsertWorkspaceApp/insertAgentApp of the component Workspace App Provisioner. The manipulation of the argument app ID results in improper authorization.
This vulnerability is known as CVE-2026-55429. It is possible to launch the attack remotely. No exploit is available.
GHSA
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
ghsa·2026-07-06
CVE-2026-55429 [HIGH] CWE-639 Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
### Summary
`UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` accepts the app ID from the provisioner's `CompleteJob` payload without verifying it belongs to the workspace being built. `CompleteJob` runs under `dbauthz.AsProvisionerd` so the authorization layer does not block the cross-workspace upsert.
> **Note:** Exploitation requires elevated access as a template author or external provisioner operator.
### Impact
A user with template authorship or external provisioner access can submit a `CompleteJob` payload with a known victim app UUID and an attacker-controlled agent ID. On completion of the attacker's build the victim's app ro
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/coder/coder/pull/26103https://github.com/coder/coder/releases/tag/v2.29.17https://github.com/coder/coder/releases/tag/v2.32.7https://github.com/coder/coder/releases/tag/v2.33.8https://github.com/coder/coder/releases/tag/v2.34.2https://github.com/coder/coder/security/advisories/GHSA-9rjw-3gwp-f59v
2026-07-08
Published