CVE-2026-55435Disclosure(coder / coder)

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. Versions 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coder

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
coder

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-07: 207-07
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-55435 Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI… https://www.cve.org/CVERecord?id=CVE-2026-55435 ----- Traducción: CVE-2026-55435 Cod… http://infoflow.cloud`

    Post summary

    A new CVE-2026-55435 affecting Coder's Terraform provisioning is announced, impacting versions 2.30.0 through 2.34.2, with a link to the official CVE record provided.

    0000028
    91 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-55435 Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI… https://www.cve.org/CVERecord?id=CVE-2026-55435

    Post summary

    The snippet briefly references CVE‑2026‑55435 affecting Coder’s Terraform‑enabled remote development environments, listing affected version ranges but providing no details on PoCs, exploits, patches, or technical specifics.

    00000716
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcodercoder-go-

Explore more