CVE-2026-46354: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
Summary
azureidentity.Validate() verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. {"vmId":"<target>"} and the forged vmId will be accepted returning the victim workspace agent's session token.
No authentication is required. The attacker only needs to know a target VM's vmId which is a UUIDv4. that's a practical limitation which would typically require prior access to be exploited
Root Cause
In unpatched Coder releases the signature over the PKCS#7 content is not validated - only the signing certificate is checked.
Impact
An attacker on any Azure VM or with access to a publicly available Azure IMDS certificate from CT logs can:
1. Steal an agent session token by sending a forged PKCS#7 envelope to POST /api/v2/workspaceagents/azure-instance-identity which is unauthenticated. 2. With the stolen token access: - Git SSH private key via GET /workspaceagents/me/gitsshkey: push to repositories and impersonate the workspace owner. - OAuth access tokens via GET /workspaceagents/me/external-auth: GitHub, GitLab, and Bitbucket tokens in plaintext. - Workspace secrets via the agent manifest: environment variables, file paths, and API keys.
Attack Path Diagram
<img width="5588" height="4176" alt="PKCS7diagram (1)" src="https://github.com/user-attachments/assets/74e88a89-a995-450d-87ab-6feed03579a5" />
Affected Versions
All versions of Coder v2 are affected.
Patches
Fixed in #25286
The fix was backported to all supported release lines:
| Patched Versions | | --- | | v2.33.3 | | v2.32.2 | | v2.31.12 | | v2.30.8 | | v2.29.13 | | v2.24.5 |
Workarounds
If unable to patch we recommend immediately reconfiguring any Azure templates to use token authentication rather than azure-instance-identity until the patch is released and you are fully upgraded.
1. Modify the coderagent.auth value to be token. 2. Add CODERAGENTTOKEN=${coderagent.main.token} to the set of environment variables for the Coder Workspace Agent initialization script.
Recognition
We'd like to thank Ben Tran of calif.io and Anthropic’s Security Team (ANT-2026-22445) for independently disclosing this issue!
Other sources
Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, azureidentity.Validate() verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. {"vmId":"<target>"} and the forged vmId will be accepted returning the victim workspace agent's session token. No authentication is required. The attacker only needs to know a target VM's vmId which is a UUIDv4. That's a practical limitation which would typically require prior access to be exploited. Versions 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, reconfigure any Azure templates to use token authentication rather than azure-instance-identity.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/coder/coder/v2to a version that resolves this vulnerability.Fixed in 2.24.5 - Upgrade
Upgrade
go/github.com/coder/coder/v2to a version that resolves this vulnerability.Fixed in 2.29.13 - Upgrade
Upgrade
go/github.com/coder/coder/v2to a version that resolves this vulnerability.Fixed in 2.30.8 - Upgrade
Upgrade
go/github.com/coder/coder/v2to a version that resolves this vulnerability.Fixed in 2.31.12 - Upgrade
Upgrade
go/github.com/coder/coder/v2to a version that resolves this vulnerability.Fixed in 2.32.2 - Upgrade
Upgrade
go/github.com/coder/coder/v2to a version that resolves this vulnerability.Fixed in 2.33.3 - Upgrade
Upgrade
Coder v2to a version that resolves this vulnerability.Fixed in 2.24.5 - Upgrade
Upgrade
Coder v2to a version that resolves this vulnerability.Fixed in 2.29.13 - Upgrade
Upgrade
Coder v2to a version that resolves this vulnerability.Fixed in 2.30.8 - Upgrade
Upgrade
Coder v2to a version that resolves this vulnerability.Fixed in 2.31.12 - Upgrade
Upgrade
Coder v2to a version that resolves this vulnerability.Fixed in 2.32.2 - Upgrade
Upgrade
Coder v2to a version that resolves this vulnerability.Fixed in 2.33.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch #25286 - Configuration
Modify the `coder_agent.auth` value to be `token` (workaround until upgraded), rather than using `azure-instance-identity`.
Coder (Terraform) agent auth configuration coder_agent.auth = token - Configuration
Add `CODER_AGENT_TOKEN=${coder_agent.main.token}` to the set of environment variables for the Coder Workspace Agent initialization script.
Coder Workspace Agent initialization script CODER_AGENT_TOKEN = ${coder_agent.main.token} - Compensating control
Reconfigure Azure templates to use token authentication rather than `azure-instance-identity` until you are fully upgraded and patched.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46354?
The severity of CVE-2026-46354 is critical with a score of 9.1.
How do I fix CVE-2026-46354?
To fix CVE-2026-46354, update to the latest version of the affected software as provided in the official releases.
What impact does CVE-2026-46354 have on my system?
CVE-2026-46354 allows an attacker to embed a forged `vmId` alongside a legitimate Azure certificate, which can compromise security.
What software is affected by CVE-2026-46354?
The affected software includes go/github.com/coder/coder/v2 and go/github.com/coder/coder.
When was CVE-2026-46354 published?
CVE-2026-46354 was published on May 19, 2026.