CVE-2026-55075Disclosure(coder / coder)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch coder coder systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, two flaws in Coder's OIDC login chained into account takeover. Email-based user matching fell back to linking by email without checking for an existing link to a different IdP subject and the `email_verified` claim was only enforced when present as a boolean `false` so an absent or non-boolean claim was treated as verified. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 restricts the email fallback to first-time and legacy linking and defaults `email_verified` to false when the claim is absent or of an unexpected type. As a workaround, configure the OIDC provider to disallow self-registration or to require email verification before issuing tokens.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-289

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coder

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
coder

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-08: 1Mentions · 2026-07-09: 1PoC Mentioned / Linked · 2026-07-09: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-09: 107-0807-09
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-081
Disclosure1
2026-07-091
Patch1
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-55075 - Authentication Bypass in Coder. OIDC login flaws enable account takeover. #CVSS 7.4. Update to patched versions immediately. #CVEAlert #developers #devsecops #devops #Coder #infosec #redteam #blueteam #git #github #gitlab https://www.valtersit.com/cve/CVE-2026-55075/

    Post summary

    CVE‑2026‑55075 is an authentication bypass in Coder’s OIDC login that allows account takeover; patch to the latest version immediately.

    0000067
    974 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-55075 Coder Weak OIDC account matching could allow account takeover where email verification is not properly enforced in remote development environments Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-07-07/TIER_2_CVE-2026-55075.md #CyberSecurity #IdentitySecurity #VulnerabilityManagement

    Post summary

    The post discloses CVE‑2026‑55075, noting weak OIDC account matching that could allow account takeover, and links to a detailed analysis report but does not provide a PoC, exploit, active exploit evidence, or patch information.

    0000045
    57 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcodercoder-go-

Explore more