← Voltar à pesquisa de CVEs

CVE-2026-55077

Coder

Descrição

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePersonal` and did not prevent a `user-admin` from resetting an `owner` account-s password. It also did not require the current password when an admin reset another user-s password. Exploitation requires the privileged `user-admin` role so practical risk is limited to deployments that grant `user-admin` to less trusted operators. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 prevents non-owner users from resetting the password of an account that holds the `owner` role. As a workaround, restrict the `user-admin` role to trusted administrators.

CVSS 7.2EPSS 0.336%Risco 0.74
Ver fonte
Publicação
2026-07-07 23:16:55
Versões afetadas
<2.29.7,<2.32.7,<2.33.8,<2.34.2
Tipo
Software crítico
Vetor
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H