SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-55435

MEDIUM · CVSS 5.4 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

The vulnerability affects Coder's AI Bridge proxy endpoints in versions 2.30.0 to 2.34.1, where the authentication mechanism fails to revoke API keys for suspended users, allowing continued access through unexpired tokens. This could lead to unauthorized access if an attacker exploits a suspended account's API key. Organizations using affected versions should prioritize this issue to ensure proper access controls and mitigate potential security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55435
Severity
MEDIUM
CVSS
5.4
EPSS
0.20%

Original NVD Description

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. Versions 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`.

Related CVEs

Other vulnerabilities affecting the same vendor(s)