PT-2026-56065 · Coder · Coder

·

CVE-2026-55075

·

Published

2026-07-06

·

Updated

2026-07-30

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Coder versions prior to 2.34.2 Coder versions prior to 2.33.8 Coder versions prior to 2.32.7 Coder versions prior to 2.29.17
Description Two flaws in the OIDC login process allow for account takeover. The first issue occurs when email-based user matching falls back to linking by email without verifying if an existing link to a different Identity Provider (IdP) subject already exists. The second issue involves the email verified claim, which is only enforced when explicitly set to the boolean false; if the claim is absent or not a boolean, it is treated as verified. An attacker who can authenticate with a configured OIDC provider using an email that matches a victim's account can gain full access to that victim's workspaces, templates, and resources, provided the account is not yet linked to another IdP subject.
Recommendations Update to version 2.34.2 or newer. Update to version 2.33.8 or newer. Update to version 2.32.7 or newer. Update to version 2.29.17 or newer. Configure the OIDC provider to disallow self-registration or require email verification before issuing tokens.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55075
GHSA-9R87-MVCW-X35F
GO-2026-5908
OPENSUSE-SU-2026:21483-1

Affected Products

Coder