CVE-2026-55076General(coder / coder)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean (for example the string `"false"`) or omitted it, the assertion failed open and the email was treated as verified. Combined with an unconditional email-based account fallback, this enabled account takeover. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 coerces `email_verified` across bool, string and numeric types (fail-closed) and blocks the email fallback when the matched user already has a different linked IdP subject. As a workaround, ensure the IdP returns `email_verified` as a native JSON boolean. The email-fallback linking issue has no configuration workaround; upgrading is required.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-704

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coder

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-07-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
coder

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-07: 1Mentions · 2026-07-08: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 107-0707-08
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-55076 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback che… https://www.cve.org/CVERecord?id=CVE-2026-55076 ----- Traducción: CVE-2026-55076 Cod… http://infoflow.cloud`

    Post summary

    The post references CVE-2026-55076 and provides assorted technical details (product, versions, OIDC callback issue), but lacks information on exploits, patches, or active attacks.

    0000042
    91 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-55076 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback che… https://www.cve.org/CVERecord?id=CVE-2026-55076

    Post summary

    The post highlights an OIDC callback vulnerability in specific Coder versions but does not provide PoC, exploit code, mitigation, or evidence of active exploitation.

    00000748
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcodercoder-go-

Explore more