CVE-2026-55077: Coder
High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePersonal` and did not prevent a `user-admin` from resetting an `owner` account's password. It also did not require the current password when an admin reset another user's password. Exploitation requires the privileged `user-admin` role so practical risk is limited to deployments that grant `user-admin` to less trusted operators. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 prevents non-owner users from resetting the password of an account that holds the `owner` role. As a workaround, restrict the `user-admin` role to trusted administrators.
Affected products
- Coder Coder: before 2.29.17 (fixed in 2.29.17); from 2.30.0, before 2.32.7 (fixed in 2.32.7); from 2.33.0, before 2.33.8 (fixed in 2.33.8); from 2.34.0, before 2.34.2 (fixed in 2.34.2)
Published 2026-07-07. Last modified 2026-07-09.