Netlas.io[verified]@Netlas_ioDisclosure
A newly identified vulnerability in Coder (CVE-2026-46354) permits an attacker on any Azure VM to steal agent session tokens and obtain sensitive secrets, highlighting its severity. The post focuses on announcing the discovery and impact, without evidence of active exploitation, exploit code, or patch information.
yousukezan[verified]@yousukezanPatch
CVE‑2026‑46354 was a high‑severity authentication bypass in Coder that allowed Azure VM impersonation and token theft, but the issue has been fixed via PR #25286 and a recommended workaround is provided.
yousukezan[verified]@yousukezanPatch
The CVE‑2026‑46354 vulnerability in Coder, which allowed unauthenticated workspace takeover via forged PKCS#7 certificates, has been fixed (PR25286) and affected versions listed; a workaround of disabling Azure Instance Identity is also recommended.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The post announces CVE-2026-46354, a PKCS#7 signature bypass in Azure Instance Identity that lets unauthenticated attackers forge identity documents and steal workspace tokens; no mitigation or active exploitation details are provided.
キタきつね[verified]@foxbookDisclosure
An alert reports CVE-2026-46354, claiming it can expose Git keys and developer tokens, but offers no evidence of exploitation, detailed technical data, or mitigation steps.
Orca Security@orcasecDisclosure
The tweet alerts on CVE-2026-46354, highlighting that attackers can bypass Coder's signature verification to steal SSH keys and OAuth tokens without authentication, and directs readers to a detailed blog for deeper analysis.
Gray Hats@the_yellow_fallPatch
The tweet reports that CVE-2026-46354, a critical 9.1 CVSS token‑theft vulnerability in Azure identities, has been patched and urges users to apply the fix.