CVE-2026-55435: Suspended Coder users retain access to AI Bridge LLM proxy endpoints
Summary
AI Bridge proxy endpoints authenticate via Server.IsAuthorized in coderd/aibridgedserver, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working.
Note: Practical impact is limited to already-issued API keys of suspended users until those keys are deleted.
Impact
A suspended user with a previously issued long-lived token could continue calling AI Bridge LLM proxy endpoints, consuming paid provider resources billed to the deployment and, if injected MCP tools are enabled, invoking those tools. Access persists until the token expires, which may be months after suspension.
Patches
The fix makes AI Bridge authorization reject non-active users like the standard API key middleware. AI Bridge was introduced in v2.30.0. The v2.29 ESR line is not affected.
The fix is available in the following releases:
| Release line | Patched version | |---|---| | 2.34 | v2.34.2 | | 2.33 | v2.33.8 | | 2.32 | v2.32.7 |
Workarounds
On suspension, delete the user's API keys via DELETE /api/v2/users/{user}/keys.
Resources
- Fix: #26173
Credits
Coder would like to thank Anthropic's Security Team (ANT-2026-22446) for independently disclosing this issue!
Other sources
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via Server.IsAuthorized in coderd/aibridgedserver, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. Versions 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspension, delete the user's API keys via DELETE /api/v2/users/{user}/keys.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/coder/coder/v2to a version that resolves this vulnerability.Fixed in 2.32.7 - Upgrade
Upgrade
go/github.com/coder/coder/v2to a version that resolves this vulnerability.Fixed in 2.33.8 - Upgrade
Upgrade
go/github.com/coder/coder/v2to a version that resolves this vulnerability.Fixed in 2.34.2 - Upgrade
Upgrade
Coder AI Bridge (aibridgedserver)to a version that resolves this vulnerability.Fixed in 2.32.7Patch #26173 - Upgrade
Upgrade
Coder AI Bridge (aibridgedserver)to a version that resolves this vulnerability.Fixed in 2.33.8Patch #26173 - Upgrade
Upgrade
Coder AI Bridge (aibridgedserver)to a version that resolves this vulnerability.Fixed in 2.34.2Patch #26173 - Configuration
As a workaround, when a user is suspended, delete their long-lived API keys by running DELETE /api/v2/users/{user}/keys so previously issued tokens can no longer call AI Bridge proxy endpoints.
Coder API Delete suspended user API keys = DELETE /api/v2/users/{user}/keys
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55435?
CVE-2026-55435 has a medium severity rating of 5.4.
How do I fix CVE-2026-55435?
To fix CVE-2026-55435, ensure that suspended users are properly disabled from accessing proxy endpoints by revoking their API keys.
What are the potential risks associated with CVE-2026-55435?
The risk associated with CVE-2026-55435 is that suspended users retain unauthorized access due to unrevoked API keys.
Which software is affected by CVE-2026-55435?
CVE-2026-55435 affects the Coder Go software, specifically the AI Bridge proxy endpoints.
What authentication flaw is present in CVE-2026-55435?
CVE-2026-55435 presents an authentication flaw where suspended users can still authenticate to the AI Bridge LLM proxy due to a lack of suspension checks.