SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-46354

CRITICAL · CVSS 9.1 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

Remote development environments provisioned via Terraform in specific versions are vulnerable due to a flaw in the `azureidentity.Validate()` function, which fails to verify the PKCS#7 signature, allowing attackers to exploit this oversight. By embedding a legitimate Azure certificate with a forged `vmId`, an attacker can obtain the victim workspace agent's session token without requiring authentication, posing a significant risk to affected organizations. Organizations using the specified versions should prioritize patching or reconfiguring their Azure templates to mitigate this critical vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-46354
Severity
CRITICAL
CVSS
9.1
EPSS
0.26%

Original NVD Description

Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, `azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. `{"vmId":"<target>"}` and the forged `vmId` will be accepted returning the victim workspace agent's session token. No authentication is required. The attacker only needs to know a target VM's `vmId` which is a `UUIDv4`. That's a practical limitation which would typically require prior access to be exploited. Versions 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, reconfigure any Azure templates to use token authentication rather than `azure-instance-identity`.

Related CVEs

Other vulnerabilities affecting the same vendor(s)