CVE-2026-55077Disclosure(coder / coder)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch coder coder systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePersonal` and did not prevent a `user-admin` from resetting an `owner` account's password. It also did not require the current password when an admin reset another user's password. Exploitation requires the privileged `user-admin` role so practical risk is limited to deployments that grant `user-admin` to less trusted operators. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 prevents non-owner users from resetting the password of an account that holds the `owner` role. As a workaround, restrict the `user-admin` role to trusted administrators.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coder

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
coder

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-07: 1Mentions · 2026-07-08: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 107-0707-08
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-071
Disclosure1
2026-07-081
Patch1
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-55077 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `PUT /api/v2/users/{u… https://www.cve.org/CVERecord?id=CVE-2026-55077 ----- Traducción: CVE-2026-55077 Cod… http://infoflow.cloud`

    Post summary

    The post reports CVE-2026-55077 affecting certain Coder releases, identifies specific vulnerable versions, but does not provide PoC, exploit code, or evidence of active exploitation.

    0000031
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-55077 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `PUT /api/v2/users/{u… https://www.cve.org/CVERecord?id=CVE-2026-55077

    Post summary

    The excerpt references CVE‑2026‑55077 and lists vulnerable Coder versions along with an API endpoint, but offers no PoC, exploit code, or active exploitation details, appearing as a minimal disclosure.

    00000756
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcodercoder-go-

Explore more