CVE-2026-55176: Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SHARED_SECRET` bearer token

Published Sep 30, 2026
·
Updated

Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINERSHAREDSECRET as a bearer token without verifying which workspace the caller belongs to. Because that secret is set identically on every container in the Fly app and is reachable from the user-facing process environment inside each workspace, any tenant can use it to authenticate to any other tenant's workspace API. The result is cross-workspace read, write, and destructive-restore primitives reachable from any paying customer's shell. The existing per-workspace token check (workspaceTokenMatches) protects the user-facing per-workspace token path, but the shared-secret bearer path bypasses it entirely. At time of publication, there are no publicly known patches.

Affected Software

1 affected component
Soft Machine Soft Machine<=0.2.247

Event History

Sep 30, 2026
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments are exposed when CONTAINER_SHARED_SECRET is identical across workspace containers and is available from the user-facing process environment within each workspace. The issue affects Soft Machine versions 0.2.247 and earlier.

2

What access does an attacker need to exploit this?

An attacker needs access to a paying customer's workspace shell, where they can reach the user-facing process environment and obtain the shared bearer secret. They can then present that secret to authenticate to another tenant's workspace API.

3

Does the per-workspace token validation prevent this attack?

No. The per-workspace workspaceTokenMatches validation applies to the per-workspace token path, but the shared-secret bearer-token path bypasses that check entirely.

4

Is a patch available?

At the time of publication, there are no publicly known patches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203