Remote Development Environment Vulnerability in Coder Products

⚠️ CVE-Referenzen: CVE-2026-46354
Coder - Coder - CRITICAL - CVE-2026-46354. The Coder product provides capabilities for provisioning remote development environments through Terraform. In specific versions, the `azureidentity.Validate()` method improperly verifies PKCS#7 signer certificate chains against a trusted Azure CA without validating the PKCS#7 signature itself. This oversight allows an attacker, who only needs knowledge of a target VM's `vmId`, to craft a legitimate Azure certificate embedded with arbitrary content. As a result, the forged `vmId` may be accepted, granting the attacker unauthorized access to the victim's workspace agent's session token. Relevant versions have been updated to address this oversight, and users are advised to implement token authentication in their Azure templates as a temporary measure.
Quelle: securityvulnerability.io