CVE-2026-55077: Coder: User-admin role can reset owner account password

Published Jul 6, 2026
·
Updated

Summary

The PUT /api/v2/users/{user}/password endpoint authorized only ActionUpdatePersonal and did not prevent a user-admin from resetting an owner account's password. It also did not require the current password when an admin reset another user's password.

Note: Exploitation requires the privileged user-admin role so practical risk is limited to deployments that grant user-admin to less trusted operators.

Impact

A user-admin could reset any owner's password without knowing it, authenticate as that owner and gain full deployment control, including templates, workspaces, licensing, organization settings and the ability to self-assign the owner role. This was a privilege escalation from user-admin to owner.

Patches

The fix prevents non-owner users from resetting the password of an account that holds the owner role.

The fix was backported to all supported release lines:

| Release line | Patched version | |---|---| | 2.34 | v2.34.2 | | 2.33 | v2.33.8 | | 2.32 | v2.32.7 | | 2.29 (ESR) | v2.29.17 |

Workarounds

Restrict the user-admin role to trusted administrators until upgrading.

Resources - Fix: #25709

Credits

Coder would like to thank Anthropic's Security Team (ANT-2026-22436) for independently disclosing this issue!

Other sources

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the PUT /api/v2/users/{user}/password endpoint authorized only ActionUpdatePersonal and did not prevent a user-admin from resetting an owner account's password. It also did not require the current password when an admin reset another user's password. Exploitation requires the privileged user-admin role so practical risk is limited to deployments that grant user-admin to less trusted operators. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 prevents non-owner users from resetting the password of an account that holds the owner role. As a workaround, restrict the user-admin role to trusted administrators.

MITRE

Affected Software

8 affected componentsFixes available
go/github.com/coder/coder/v2<2.29.17
2.29.17
go/github.com/coder/coder/v2>=2.30.0<2.32.7
2.32.7
go/github.com/coder/coder/v2>=2.33.0<2.33.8
2.33.8
go/github.com/coder/coder/v2>=2.34.0<2.34.2
2.34.2
Coder Coder Go<2.29.17
Coder Coder Go>=2.30.0<2.32.7
Coder Coder Go>=2.33.0<2.33.8
Coder Coder Go>=2.34.0<2.34.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.29.17
  2. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.32.7
  3. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.33.8
  4. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.34.2
  5. Upgrade

    Upgrade Coder to a version that resolves this vulnerability.

    Fixed in 2.29.17
  6. Upgrade

    Upgrade Coder to a version that resolves this vulnerability.

    Fixed in 2.32.7
  7. Upgrade

    Upgrade Coder to a version that resolves this vulnerability.

    Fixed in 2.33.8
  8. Upgrade

    Upgrade Coder to a version that resolves this vulnerability.

    Fixed in 2.34.2
  9. Configuration

    As a workaround until upgrading, restrict the `user-admin` role to trusted administrators.

    Coder role-based access control Restrict `user-admin` role assignment = trusted administrators only

Event History

Jul 6, 2026
Advisory Published
via GitHub·08:53 PM
Data Sourced
via GitHub·08:53 PM
DescriptionSeverityWeaknessAffected Software
Jul 7, 2026
CVE Published
via MITRE·10:44 PM
Data Sourced
via MITRE·10:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-55077?

CVE-2026-55077 has a high severity rating of 7.2.

2

How do I fix CVE-2026-55077?

To fix CVE-2026-55077, ensure that you implement proper authorization checks for the `PUT /api/v2/users/{user}/password` endpoint.

3

What impact does CVE-2026-55077 pose?

CVE-2026-55077 allows a user-admin to reset the password of an owner account, potentially leading to unauthorized access.

4

Can a user-admin reset any user's password with CVE-2026-55077?

Yes, the vulnerability allows a user-admin to reset any user's password without requiring the current password.

5

What software is affected by CVE-2026-55077?

CVE-2026-55077 affects the Coder application in version 2 of its Go implementation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203