CVE-2026-55435
published 2026-07-07CVE-2026-55435: Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and…
PriorityP335medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.32%
24.7th percentile
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. Versions 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | >= 2.30.0 < 2.32.7 | 2.32.7 |
| coder | coder | >= 2.33.0 < 2.33.8 | 2.33.8 |
| coder | coder | >= 2.34.0 < 2.34.2 | 2.34.2 |
| github.com | coder_coder_v2 | >= 2.30.0 < 2.32.7 | 2.32.7 |
| github.com | coder_coder_v2 | >= 2.33.0 < 2.33.8 | 2.33.8 |
| github.com | coder_coder_v2 | >= 2.34.0 < 2.34.2 | 2.34.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Coder up to 2.32.6/2.33.7/2.34.1 AI Bridge Proxy Endpoint coderd/aibridgedserver IsAuthorized improper authorization
vuldb·2026-07-07·CVSS 5.4
CVE-2026-55435 [MEDIUM] Coder up to 2.32.6/2.33.7/2.34.1 AI Bridge Proxy Endpoint coderd/aibridgedserver IsAuthorized improper authorization
A vulnerability described as problematic has been identified in Coder up to 2.32.6/2.33.7/2.34.1. The affected element is the function IsAuthorized of the file coderd/aibridgedserver of the component AI Bridge Proxy Endpoint. The manipulation results in improper authorization.
This vulnerability was named CVE-2026-55435. The attack may be performed from remote. There is no available exploit.
GHSA
Suspended Coder users retain access to AI Bridge LLM proxy endpoints
ghsa·2026-07-06
CVE-2026-55435 [MEDIUM] CWE-863 Suspended Coder users retain access to AI Bridge LLM proxy endpoints
Suspended Coder users retain access to AI Bridge LLM proxy endpoints
### Summary
AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working.
> **Note:** Practical impact is limited to already-issued API keys of suspended users until those keys are deleted.
### Impact
A suspended user with a previously issued long-lived token could continue calling AI Bridge LLM proxy endpoints, consuming paid provider resources billed to the deployment and, if injected MCP tools are enabled, invoking those tools. Access persists until the token
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/coder/coder/commit/0d2c9f904a8b75b888140fcc8fbf4633660cc787https://github.com/coder/coder/pull/26164https://github.com/coder/coder/pull/26173https://github.com/coder/coder/releases/tag/v2.32.7https://github.com/coder/coder/releases/tag/v2.33.8https://github.com/coder/coder/releases/tag/v2.34.2https://github.com/coder/coder/security/advisories/GHSA-wqxv-w64v-5wh6
2026-07-07
Published