CVE-2026-46354

github.com/coder/coder: Improper Verification of Cryptographic Signature (CVE-2026-46354)

criticalEPSS 0.3%

Affected

  • go/github.com/coder/coder/v2 2.33.0-rc.0..*
  • go/github.com/coder/coder/v2 2.32.0-rc.0..*
  • go/github.com/coder/coder/v2 2.31.0..*
  • go/github.com/coder/coder/v2 2.30.0..*
  • go/github.com/coder/coder/v2 2.29.0..*

Description

Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, `azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. `{"vmId":"<target>"}` and the forged `vmId` will be accepted returning the victim workspace agent's session token. No authentication is required. The attacker only needs to know a target VM's `vmId` which is a `UUIDv4`. That's a practical limitation which would typically require prior access to be exploited. Versions 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, reconfigure any Azure templates to use token authentication rather than `azure-instance-identity`.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

gogithub.com/coder/coder
gogithub.com/coder/coder/v2
2.29.02.30.02.31.02.32.0-rc.02.33.0-rc.0

Metrics

9.1
Source: nvd-v3
22.8 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
critical
no public PoC known
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-07 21:10 UTC
CWE-347

Weakness classes (CWE)

  • CWE-347Base

    Improper Verification of Cryptographic Signature

    The product does not verify, or incorrectly verifies, the cryptographic signature for data.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. New CVE Received2026-07-07 22:16 UTC· security-advisories@github.com
    • Affected: coder
    • Description: Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, `azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. `{"vmId":"<target>"}` and the forged `vmId` will be accepted returning the victim workspace agent's session token. No authentication is required. The attacker only needs to know a target VM's `vmId` which is a `UUIDv4`. That's a practical limitation which would typically require prior access to be exploited. Versions 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, reconfigure any Azure templates to use token authentication rather than `azure-instance-identity`.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
    • CWE: CWE-347

Linked advisories