CVE-2026-55077: Coder: User-admin role can reset owner account password
Summary
The PUT /api/v2/users/{user}/password endpoint authorized only ActionUpdatePersonal and did not prevent a user-admin from resetting an owner account's password. It also did not require the current password when an admin reset another user's password.
Note: Exploitation requires the privileged user-admin role so practical risk is limited to deployments that grant user-admin to less trusted operators.
Impact
A user-admin could reset any owner's password without knowing it, authenticate as that owner and gain full deployment control, including templates, workspaces, licensing, organization settings and the ability to self-assign the owner role. This was a privilege escalation from user-admin to owner.
Patches
The fix prevents non-owner users from resetting the password of an account that holds the owner role.
The fix was backported to all supported release lines:
| Release line | Patched version | |---|---| | 2.34 | v2.34.2 | | 2.33 | v2.33.8 | | 2.32 | v2.32.7 | | 2.29 (ESR) | v2.29.17 |
Workarounds
Restrict the user-admin role to trusted administrators until upgrading.
Resources - Fix: #25709
Credits
Coder would like to thank Anthropic's Security Team (ANT-2026-22436) for independently disclosing this issue!
Other sources
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the PUT /api/v2/users/{user}/password endpoint authorized only ActionUpdatePersonal and did not prevent a user-admin from resetting an owner account's password. It also did not require the current password when an admin reset another user's password. Exploitation requires the privileged user-admin role so practical risk is limited to deployments that grant user-admin to less trusted operators. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 prevents non-owner users from resetting the password of an account that holds the owner role. As a workaround, restrict the user-admin role to trusted administrators.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/coder/coder/v2to a version that resolves this vulnerability.Fixed in 2.29.17 - Upgrade
Upgrade
go/github.com/coder/coder/v2to a version that resolves this vulnerability.Fixed in 2.32.7 - Upgrade
Upgrade
go/github.com/coder/coder/v2to a version that resolves this vulnerability.Fixed in 2.33.8 - Upgrade
Upgrade
go/github.com/coder/coder/v2to a version that resolves this vulnerability.Fixed in 2.34.2 - Upgrade
Upgrade
Coderto a version that resolves this vulnerability.Fixed in 2.29.17 - Upgrade
Upgrade
Coderto a version that resolves this vulnerability.Fixed in 2.32.7 - Upgrade
Upgrade
Coderto a version that resolves this vulnerability.Fixed in 2.33.8 - Upgrade
Upgrade
Coderto a version that resolves this vulnerability.Fixed in 2.34.2 - Configuration
As a workaround until upgrading, restrict the `user-admin` role to trusted administrators.
Coder role-based access control Restrict `user-admin` role assignment = trusted administrators only
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55077?
CVE-2026-55077 has a high severity rating of 7.2.
How do I fix CVE-2026-55077?
To fix CVE-2026-55077, ensure that you implement proper authorization checks for the `PUT /api/v2/users/{user}/password` endpoint.
What impact does CVE-2026-55077 pose?
CVE-2026-55077 allows a user-admin to reset the password of an owner account, potentially leading to unauthorized access.
Can a user-admin reset any user's password with CVE-2026-55077?
Yes, the vulnerability allows a user-admin to reset any user's password without requiring the current password.
What software is affected by CVE-2026-55077?
CVE-2026-55077 affects the Coder application in version 2 of its Go implementation.