{"id":"CVE-2026-46354","aliases":["GHSA-6x44-w3xg-hqqf","GO-2026-5196"],"url":"https://o3.security/vulnerability/CVE-2026-46354","summary":"Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft","details":"Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, `azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. `{\"vmId\":\"<target>\"}` and the forged `vmId` will be accepted returning the victim workspace agent's session token. No authentication is required. The attacker only needs to know a target VM's `vmId` which is a `UUIDv4`. That's a practical limitation which would typically require prior access to be exploited. Versions 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, reconfigure any Azure templates to use token authentication rather than `azure-instance-identity`.","published":"2026-07-07T21:10:01.899Z","modified":"2026-08-12T03:51:26.588822725Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":{"score":0.0026,"percentile":0.1789,"asOf":"2026-08-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/coder/coder/v2","fixedVersion":"2.33.3"},{"ecosystem":"Go","name":"github.com/coder/coder/v2","fixedVersion":"2.32.2"},{"ecosystem":"Go","name":"github.com/coder/coder/v2","fixedVersion":"2.31.12"},{"ecosystem":"Go","name":"github.com/coder/coder/v2","fixedVersion":"2.30.8"},{"ecosystem":"Go","name":"github.com/coder/coder/v2","fixedVersion":"2.29.13"},{"ecosystem":"Go","name":"github.com/coder/coder/v2","fixedVersion":"2.24.5"},{"ecosystem":"Go","name":"github.com/coder/coder","fixedVersion":null}],"fix":{"url":"https://github.com/coder/coder/pull/25286","label":"coder/coder#25286"},"references":[{"type":"WEB","url":"https://github.com/coder/coder/releases/tag/v2.24.5"},{"type":"WEB","url":"https://github.com/coder/coder/releases/tag/v2.29.13"},{"type":"WEB","url":"https://github.com/coder/coder/releases/tag/v2.30.8"},{"type":"WEB","url":"https://github.com/coder/coder/releases/tag/v2.31.12"},{"type":"WEB","url":"https://github.com/coder/coder/releases/tag/v2.32.2"},{"type":"WEB","url":"https://github.com/coder/coder/releases/tag/v2.33.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46354.json"},{"type":"ADVISORY","url":"https://github.com/coder/coder/security/advisories/GHSA-6x44-w3xg-hqqf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46354"},{"type":"FIX","url":"https://github.com/coder/coder/pull/25286"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.588822725Z"}}