AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-55429

HIGH · CVSS 8.7 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability affects the Coder platform, specifically the `UpsertWorkspaceApp` and `insertAgentApp` functions, which improperly handle agent IDs during workspace provisioning, allowing for unauthorized cross-workspace app assignments. This can lead to potential privilege escalation if exploited by users with elevated access, such as template authors or external provisioner operators. Organizations utilizing affected versions should prioritize upgrading to versions 2.29.7, 2.32.7, 2.33.8, or 2.34.2 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55429
Severity
HIGH
CVSS
8.7
EPSS
0.29%

Original NVD Description

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` accepts the app ID from the provisioner's `CompleteJob` payload without verifying it belongs to the workspace being built. `CompleteJob` runs under `dbauthz.AsProvisionerd` so the authorization layer does not block the cross-workspace upsert. Exploitation requires elevated access as a template author or external provisioner operator. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 verifies that any existing `workspace_apps` row matching the supplied ID belongs to the workspace being built and rejects cross-workspace agent reassignment. No known workarounds are available.

Related CVEs

Other vulnerabilities affecting the same vendor(s)