Answer in brief
CVE-2026-55433 records a Medium severity (CVSS 5.4) missing auth vulnerability in Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers. The source record does not mark it as known exploited. 4 affected packages are mapped in the feed.
Answer in brief
CVE-2026-55433 records a Medium severity (CVSS 5.4) missing auth vulnerability in Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers. The source record does not mark it as known exploited. 4 affected packages are mapped in the feed.
Update github.com/coder/coder/v2 to 2.34.2; github.com/coder/coder/v2 to 2.33.8; github.com/coder/coder/v2 to 2.32.7; github.com/coder/coder/v2 to 2.29.17 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanMissing Auth describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-55433 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/coder/coder/v2go | >=2.34.0,<2.34.2 | 2.34.2 |
| github.com/coder/coder/v2go | >=2.33.0,<2.33.8 | 2.33.8 |
| github.com/coder/coder/v2go | >=2.30.0,<2.32.7 | 2.32.7 |
| github.com/coder/coder/v2go | <2.29.17 | 2.29.17 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-55433 records a Medium severity (CVSS 5.4) missing auth vulnerability in Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers. The source record does not mark it as known exploited. 4 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate github.com/coder/coder/v2 to 2.34.2; github.com/coder/coder/v2 to 2.33.8; github.com/coder/coder/v2 to 2.32.7; github.com/coder/coder/v2 to 2.29.17 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanMissing Auth describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-55433 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/coder/coder/v2go | >=2.34.0,<2.34.2 | 2.34.2 |
| github.com/coder/coder/v2go | >=2.33.0,<2.33.8 | 2.33.8 |
| github.com/coder/coder/v2go | >=2.30.0,<2.32.7 | 2.32.7 |
| github.com/coder/coder/v2go | <2.29.17 | 2.29.17 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-55433 records a Medium severity (CVSS 5.4) missing auth vulnerability in Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers. The source record does not mark it as known exploited. 4 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard### Summary The devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild. > **Note:** Exploitation requires an existing low-privilege role with access to the target workspace. ### Impact Any authenticated principal with read-only workspace access, such as a Template Admin or Org Template Admin, could recreate a devcontainer, destroying uncommitted in-container state and, if called repeatedly, denying service. This is an authorization bypass leading to data loss and denial of service. ### Patches The fix adds an explicit `ActionUpdate` authorization check before the agent is dialed like the delete endpoint. The fix was backported to all supported release lines: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) | ### Workarounds None. ### Resources - Fix: #25812 ### Credits Coder would like to thank Anthropic's Security Team (ANT-2026-22454) for independently disclosing this issue!
### Summary The devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild. > **Note:** Exploitation requires an existing low-privilege role with access to the target workspace. ### Impact Any authenticated principal with read-only workspace access, such as a Template Admin or Org Template Admin, could recreate a devcontainer, destroying uncommitted in-container state and, if called repeatedly, denying service. This is an authorization bypass leading to data loss and denial of service. ### Patches The fix adds an explicit `ActionUpdate` authorization check before the agent is dialed like the delete endpoint. The fix was backported to all supported release lines: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) | ### Workarounds None. ### Resources - Fix: #25812 ### Credits Coder would like to thank Anthropic's Security Team (ANT-2026-22454) for independently disclosing this issue!