# CVE-2026-55075

## Summary

- **CVE ID:** CVE-2026-55075
- **Severity:** HIGH
- **CVSS Score:** 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-287, CWE-289
- **Published:** Jul 7, 2026
- **Last Modified:** Jul 8, 2026

## Description

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, two flaws in Coder's OIDC login chained into account takeover. Email-based user matching fell back to linking by email without checking for an existing link to a different IdP subject and the `email_verified` claim was only enforced when present as a boolean `false` so an absent or non-boolean claim was treated as verified. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 restricts the email fallback to first-time and legacy linking and defaults `email_verified` to false when the claim is absent or of an unexpected type. As a workaround, configure the OIDC provider to disallow self-registration or to require email verification before issuing tokens.

## Affected Products

- coder — coder (>= 2.34.0, < 2.34.2)
- coder — coder (>= 2.33.0, < 2.33.8)
- coder — coder (>= 2.30.0, < 2.32.7)
- coder — coder (< 2.29.17)

## References

- [CNA](https://github.com/coder/coder/security/advisories/GHSA-9r87-mvcw-x35f)
- [CNA](https://github.com/coder/coder/pull/25712)
- [CNA](https://github.com/coder/coder/pull/25713)
- [CNA](https://github.com/coder/coder/releases/tag/v2.29.17)
- [CNA](https://github.com/coder/coder/releases/tag/v2.32.7)
- [CNA](https://github.com/coder/coder/releases/tag/v2.33.8)
- [CNA](https://github.com/coder/coder/releases/tag/v2.34.2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.48%
- **EPSS Percentile:** 39.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._