Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-46354

Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
Back to all
CVE

CVE-2026-46354

Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft

Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, azureidentity.Validate() verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. {"vmId":"<target>"} and the forged vmId will be accepted returning the victim workspace agent's session token. No authentication is required. The attacker only needs to know a target VM's vmId which is a UUIDv4. That's a practical limitation which would typically require prior access to be exploited. Versions 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, reconfigure any Azure templates to use token authentication rather than azure-instance-identity.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.1
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
C
H
U
-

Related Resources

No items found.

References

https://github.com/coder/coder/releases/tag/v2.24.5, https://github.com/coder/coder/releases/tag/v2.29.13, https://github.com/coder/coder/releases/tag/v2.30.8, https://github.com/coder/coder/releases/tag/v2.31.12, https://github.com/coder/coder/releases/tag/v2.32.2, https://github.com/coder/coder/releases/tag/v2.33.3, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46354.json, https://github.com/coder/coder/security/advisories/GHSA-6x44-w3xg-hqqf, https://nvd.nist.gov/vuln/detail/CVE-2026-46354, https://github.com/coder/coder/pull/25286

Severity

9.1

CVSS Score
0
10

Basic Information

Base CVSS
9.1
EPSS Probability
0.00318%
EPSS Percentile
0.22419%
Introduced Version
f009c17217e6bad9a61ba511d23735bc1ce94da0
Fix Available
2b778f292c2ddf8ac261683d0d5d8a18da1512f6

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading