logo

Signature Bypass Alert: Critical Coder Flaw (CVE-2026-46354) Exposes Git Keys and Developer Tokens

ID: e76c3a1a-6f0a-5685-aeba-f5972651325d

STIX ID: report--e76c3a1a-6f0a-5685-aeba-f5972651325d

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Ddos

...
...

Coder patched CVE-2026-46354, a critical (CVSS 9.1) flaw in its Azure instance identity validation: azureidentity.Validate() checks signer certificates but does not verify PKCS#7 signatures, allowing unauthenticated attackers who can supply a target vmid to forge instance identity, receive workspace agent tokens via POST /api/v2/workspaceagents/azure-instance-identity, and use those tokens to exfiltrate OAuth tokens, Git SSH private keys, and workspace secrets; administrators should update to the listed patched versions or disable the vulnerable Azure identity channel and switch to token authentication as a temporary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.