CVE-2026-55432: Coder allows organizations to provision remote develop
CVE-2026-55432 analysis covering impact, affected products, versions, remediation, and cross-checked defender guidance.
CVE-2026-55432 is a vulnerability published by NVD on 7/8/2026.
What happened
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `CreateSubAgent` RPC did not validate a requested app sharing level against the template's `MaxPortSharingLevel` before persisting workspace apps, letting a workspace owner exceed the administrator's configured maximum. Exploitation requires the ability to register sub-agent apps in a workspace the attacker controls. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2clamps the sub-agent app sharing level to the template's `MaxPortSharingLevel`. As a workaround, disable wildcard app hostnames (`CODER_WILDCARD_ACCESS_URL`) to block subdomain-based app routing.
Affected products and versions
- coder coder unspecified version (before 2.29.17)
- coder coder unspecified version (from 2.30.0 before 2.32.7)
- coder coder unspecified version (from 2.33.0 before 2.33.8)
- coder coder unspecified version (from 2.34.0 before 2.34.2)
Severity and weakness
CVSS: MEDIUM 5.4. Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N.
Weaknesses: CWE-862.
Known exploitation
No CISA KEV entry is currently attached to the NVD record.
What defenders should do
- Identify whether the affected product and version range exists in production.
- Review vendor advisories and release notes before change windows.
- Patch, upgrade, disable the vulnerable component, or apply vendor mitigations.
- Verify the running version after deployment, not only the package inventory.
Official and supporting references
- https://github.com/coder/coder/pull/26061
- https://github.com/coder/coder/releases/tag/v2.29.17
- https://github.com/coder/coder/releases/tag/v2.32.7
- https://github.com/coder/coder/releases/tag/v2.33.8
- https://github.com/coder/coder/releases/tag/v2.34.2
- https://github.com/coder/coder/security/advisories/GHSA-x9qq-2qh5-8rxf