CVE-2026-55433
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2,
CVSS
5.4
Medium
EPSS
0.4%
p32
KEV
—
Exploit Today
10
0-100
Published: Jul 8, 2026 · Last modified: Jul 8, 2026 · CWE-862
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild. Exploitation requires an existing low-privilege role with access to the target workspace. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 adds an explicit `ActionUpdate` authorization check before the agent is dialed like the delete endpoint. No known workarounds are available.
- github.comhttps://github.com/coder/coder/pull/25812
- github.comhttps://github.com/coder/coder/releases/tag/v2.29.17
- github.comhttps://github.com/coder/coder/releases/tag/v2.32.7
- github.comhttps://github.com/coder/coder/releases/tag/v2.33.8
- github.comhttps://github.com/coder/coder/releases/tag/v2.34.2
- github.comhttps://github.com/coder/coder/security/advisories/GHSA-jqj2-x4c5-jfxm