{"id":"CVE-2026-46354","aliases":["GHSA-6x44-w3xg-hqqf","GO-2026-5196"],"url":"https://o3.security/vulnerability/CVE-2026-46354","summary":"Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft","details":"## Summary\n\n`azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. `{\"vmId\":\"<target>\"}` and the forged `vmId` will be accepted returning the victim workspace agent's session token.\n\n**No authentication is required.** The attacker only needs to know a target VM's `vmId` which is a `UUIDv4`.\n> that's a practical limitation which would typically require prior access to be exploited\n\n## Root Cause\n\nIn unpatched Coder releases the signature over the PKCS#7 content is not validated - only the signing certificate is checked.\n\n## Impact\n\nAn attacker on any Azure VM or with access to a publicly available Azure IMDS certificate from CT logs can:\n\n1. **Steal an agent session token** by sending a forged PKCS#7 envelope to `POST /api/v2/workspaceagents/azure-instance-identity` which is unauthenticated.\n2. **With the stolen token** access:\n   - **Git SSH private key** via `GET /workspaceagents/me/gitsshkey`: push to repositories and impersonate the workspace owner.\n   - **OAuth access tokens** via `GET /workspaceagents/me/external-auth`: GitHub, GitLab, and Bitbucket tokens in plaintext.\n   - **Workspace secrets** via the agent manifest: environment variables, file paths, and API keys.\n\n## Attack Path Diagram\n\n<img width=\"5588\" height=\"4176\" alt=\"PKCS7_diagram (1)\" src=\"https://github.com/user-attachments/assets/74e88a89-a995-450d-87ab-6feed03579a5\" />\n\n## Affected Versions\n\nAll versions of Coder v2 are affected.\n\n## Patches\n\nFixed in [#25286 ](https://github.com/coder/coder/pull/25286)\n\nThe fix was backported to all supported release lines:\n\n| Patched Versions |\n| --- |\n| [**v2.33.3**](https://github.com/coder/coder/releases/tag/v2.33.3) |\n| [**v2.32.2**](https://github.com/coder/coder/releases/tag/v2.32.2) |\n| [**v2.31.12**](https://github.com/coder/coder/releases/tag/v2.31.12) |\n| [**v2.30.8**](https://github.com/coder/coder/releases/tag/v2.30.8) |\n| [**v2.29.13**](https://github.com/coder/coder/releases/tag/v2.29.13) |\n| [**v2.24.5**](https://github.com/coder/coder/releases/tag/v2.24.5) |\n\n## Workarounds\n\nIf unable to patch we recommend immediately reconfiguring any Azure templates to use token authentication rather than `azure-instance-identity` until the patch is released and you are fully upgraded.\n\n1. Modify the [`coder_agent.auth`](https://registry.terraform.io/providers/coder/coder/latest/docs/resources/agent#auth-1) value to be `token`.\n2. Add `CODER_AGENT_TOKEN=${coder_agent.main.token}` to the set of environment variables for the Coder Workspace Agent initialization script.\n\n## Recognition\n\nWe'd like to thank [Ben Tran](https://github.com/bencalif) of [calif.io](http://calif.io) and Anthropic’s Security Team (`ANT-2026-22445`) for independently disclosing this issue!","published":"2026-07-07T21:10:01.899Z","modified":"2026-08-12T03:51:26.588822725Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":{"score":0.00318,"percentile":0.23987,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/coder/coder/v2","fixedVersion":"2.33.3"},{"ecosystem":"Go","name":"github.com/coder/coder/v2","fixedVersion":"2.32.2"},{"ecosystem":"Go","name":"github.com/coder/coder/v2","fixedVersion":"2.31.12"},{"ecosystem":"Go","name":"github.com/coder/coder/v2","fixedVersion":"2.30.8"},{"ecosystem":"Go","name":"github.com/coder/coder/v2","fixedVersion":"2.29.13"},{"ecosystem":"Go","name":"github.com/coder/coder/v2","fixedVersion":"2.24.5"},{"ecosystem":"Go","name":"github.com/coder/coder","fixedVersion":null}],"fix":{"url":"https://github.com/coder/coder/pull/25286","label":"coder/coder#25286"},"references":[{"type":"WEB","url":"https://github.com/coder/coder/releases/tag/v2.24.5"},{"type":"WEB","url":"https://github.com/coder/coder/releases/tag/v2.29.13"},{"type":"WEB","url":"https://github.com/coder/coder/releases/tag/v2.30.8"},{"type":"WEB","url":"https://github.com/coder/coder/releases/tag/v2.31.12"},{"type":"WEB","url":"https://github.com/coder/coder/releases/tag/v2.32.2"},{"type":"WEB","url":"https://github.com/coder/coder/releases/tag/v2.33.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46354.json"},{"type":"ADVISORY","url":"https://github.com/coder/coder/security/advisories/GHSA-6x44-w3xg-hqqf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46354"},{"type":"FIX","url":"https://github.com/coder/coder/pull/25286"},{"type":"PACKAGE","url":"https://github.com/coder/coder"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.588822725Z"}}