cbcvebase.
CVE-2026-55435
published 2026-07-07

CVE-2026-55435: Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and…

PriorityP335medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.32%
24.7th percentile
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. Versions 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`.

Affected

9 ranges
VendorProductVersion rangeFixed in
codercoder——
codercoder——
codercoder——
codercoder>= 2.30.0 < 2.32.72.32.7
codercoder>= 2.33.0 < 2.33.82.33.8
codercoder>= 2.34.0 < 2.34.22.34.2
github.comcoder_coder_v2>= 2.30.0 < 2.32.72.32.7
github.comcoder_coder_v2>= 2.33.0 < 2.33.82.33.8
github.comcoder_coder_v2>= 2.34.0 < 2.34.22.34.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.