🛡️ CVE-2026-55077 — coder

🟠 CVSS 8.0 — High ✅ No Known Exploit CWE-285 NVD
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Coder: User-admin role can reset owner account password

Summary

The PUT /api/v2/users/{user}/password endpoint authorized only ActionUpdatePersonal and did not prevent a user-admin from resetting an owner account's password. It also did not require the current password when an admin reset another user's password.

> Note: Exploitation requires the privileged user-admin role so practical risk is limited to deployments that grant user-admin to less trusted operators.

Impact

A user-admin could reset any owner's password without knowing it, authenticate as that owner and gain full deployment control, including templates, workspaces, licensing, organization settings and the ability to self-assign the owner role. This was a privilege escalation from user-admin to owner.

Patches

The fix prevents non-owner users from resetting the password of an account that holds the owner role.

The fix was backported to all supported release lines:

| Release line | Patched version |

|---|---|

| 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) |

| 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) |

| 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) |

| 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) |

Workarounds

Restrict the user-admin role to trusted administrators until upgrading.

Resources

  • Fix: #25709

Credits

Coder would like to thank Anthropic's Security Team (ANT-2026-22436) for independently disclosing this issue!

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs administrative privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.

Weakness class

CVE-2026-55077 is classified as CWE-285: Improper Authorization. A request is carried out without confirming that the caller is permitted to perform it on that specific resource.

Affected software

CVE-2026-55077 is recorded against 3 packages.

  • coder (from 2.34.0 up to 2.34.2)
  • github.com/coder/coder
  • github.com/coder/coder/v2

Timeline and source

Published on 7 July 2026 and last revised on 9 July 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

github.com
github.com
github.com
github.com
github.com
github.com

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE CWE-285
Public Exploit ✅ No
Source NVD
Published 2026-07-07
Updated 2026-08-12
Modified 2026-07-09

Affected Packages

Software From version Fixed in
coder 2.34.0 2.34.2
github.com/coder/coder
github.com/coder/coder/v2

Similar Threats

Site Security Check

Is coder part of your stack?

CVE-2026-55077 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.