Junglewise Threat Intelligence

CVE-2026-55076: Coder account takeover via OIDC email verification bypass

CVE-2026-55076 · Severity: high · CVSS 7.4 · Published 2026-07-07

Technologies: github.com/coder/coder/v2 (Go), Coder, github.com/coder/coder (Go). Vendors: Go, Coder.

Executive brief

Coder, a platform for managing remote development environments, contained a flaw in how it verified user identities during login. An attacker could potentially take over a victim's account by exploiting a weakness in how the system confirms email addresses from third-party identity providers. This could lead to unauthorized access to sensitive development environments and corporate data.

Technical details

A vulnerability exists in Coder's OIDC implementation due to improper type assertion and insecure account linking logic. The OIDC callback used a Go type assertion for the 'email_verified' claim that failed open if the Identity Provider (IdP) returned a non-boolean value (like a string) or omitted the claim entirely. When combined with an unconditional email-based account fallback that matched users by email rather than a unique IdP subject, an attacker could register a victim's email at a malicious or misconfigured IdP to gain access to the victim's Coder account. The fix implements strict type coercion for the verification claim and restricts email-based fallback to first-time account linking only.

Affected products

  • Coder Coder < 2.29.17, >= 2.30.0 < 2.32.7, >= 2.33.0 < 2.33.8, >= 2.34.0 < 2.34.2

Timeline

  • 2026-05-27: other: Fixes submitted via pull requests
  • 2026-06-12: patched: Security release v2.29.17 published
  • 2026-07-07: disclosed: CVE published

References

Related threats