Signature Bypass Alert: Critical Coder Flaw (CVE-2026-46354) Exposes Git Keys and Developer Tokens
ID: e76c3a1a-6f0a-5685-aeba-f5972651325d
STIX ID: report--e76c3a1a-6f0a-5685-aeba-f5972651325d
Feed Name: securityonline.info
Coder patched CVE-2026-46354, a critical (CVSS 9.1) flaw in its Azure instance identity validation: azureidentity.Validate() checks signer certificates but does not verify PKCS#7 signatures, allowing unauthenticated attackers who can supply a target vmid to forge instance identity, receive workspace agent tokens via POST /api/v2/workspaceagents/azure-instance-identity, and use those tokens to exfiltrate OAuth tokens, Git SSH private keys, and workspace secrets; administrators should update to the listed patched versions or disable the vulnerable Azure identity channel and switch to token authentication as a temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
