CVE-2026-55435: Coder AI Bridge: suspended user auth bypass

GHSA-wqxv-w64v-5wh6 MEDIUM
Published July 6, 2026
CISO Take

Coder's AI Bridge proxy — the component that brokers calls to LLM providers on behalf of users — checks API key format, expiry, and secret but never checks whether the account has been suspended, so a suspended employee's still-valid token keeps working against LLM proxy endpoints. This matters for any organization running self-hosted Coder (5,435 downstream dependents) as an AI-enabled dev platform: an offboarded or disciplined user can keep consuming paid provider quota billed to the deployment, and if injected MCP tools are enabled, can keep invoking those tools, for as long as the token remains unexpired — potentially months. There is no public exploit or scanner template and it isn't in CISA KEV, and the CVSS 5.4 rating (PR:L, C:L/I:L/A:N) reflects that abuse requires an already-issued long-lived key rather than a broadly exploitable remote flaw, so this is an access-hygiene gap rather than an active-exploitation emergency. Patch to Coder v2.34.2, v2.33.8, or v2.32.7 (AI Bridge shipped in v2.30.0; the 2.29 ESR line is unaffected), and until patched, immediately revoke API keys for any suspended user via DELETE /api/v2/users/{user}/keys — suspension alone does not do this. Audit LLM provider billing and AI Bridge access logs for anomalous activity tied to accounts suspended in recent months.

Sources: NVD GitHub Advisory ATLAS

What is the risk?

Medium severity (CVSS 5.4) with low practical exploitability: PR:L means an attacker needs an already-provisioned, unexpired API key issued before suspension — this is not a remotely exploitable pre-auth flaw, and no public exploit or Nuclei template exists. Impact scope depends heavily on org-specific token lifetimes and whether injected MCP tools are enabled on AI Bridge; deployments with long-lived tokens and MCP tool access face materially higher exposure since abuse extends beyond LLM cost consumption to potential tool invocation. Confidentiality and integrity impact are both rated Low (C:L/I:L) and availability is unaffected (A:N), consistent with unauthorized-but-bounded API access rather than data exfiltration or system compromise. Risk rises with headcount turnover velocity — the more frequently users are suspended (terminations, policy violations, contractor rotations), the larger the cumulative exposure window across an organization.

How does the attack unfold?

Pre-suspension key issuance
A user, while still an active account, generates a long-lived AI Bridge API key for LLM proxy access.
AML.T0012
Suspension without key revocation
The organization suspends the user's account, but suspension does not revoke existing API keys, and AI Bridge's authorization check never verifies active status.
Continued proxy abuse
The suspended user keeps calling AI Bridge LLM proxy endpoints with the still-valid key, consuming paid provider quota billed to the deployment.
AML.T0096
Extended tool access / impact
If injected MCP tools are enabled, the suspended user can also invoke those agent tools via the proxy, with access persisting until the token expires, potentially months later.
AML.T0053

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Anthropic Python go >= 2.34.0, < 2.34.2 2.34.2
3.8K 5.2K dependents Pushed 4d ago 90% patched ~11d to patch Full package profile →

Do you use Anthropic Python? You're affected.

How severe is it?

CVSS 3.1
5.4 / 10
EPSS
0.3%
chance of exploitation in 30 days
Higher than 24% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Trivial

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR Low
UI None
S Unchanged
C Low
I Low
A None

What should I do?

1 step
  1. Patch immediately: upgrade to Coder v2.34.2 (2.34.x line), v2.33.8 (2.33.x line), or v2.32.7 (2.32.x line) — all three fix AI Bridge authorization to reject non-active users, matching the standard API key middleware behavior. Coder v2.29 ESR is not affected and requires no action for this issue. Until patched, treat account suspension as incomplete: whenever suspending a user, immediately run DELETE /api/v2/users/{user}/keys to revoke their API keys — this is the documented workaround and the only way to close the gap pre-patch. For detection, audit AI Bridge/LLM proxy access logs for API key usage attributed to accounts with a suspended status, and cross-reference LLM provider billing/usage dashboards for anomalous consumption after known suspension dates. Going forward, automate key revocation as part of the offboarding/suspension workflow instead of relying on a manual step, and consider shortening API key TTLs for accounts with AI Bridge access.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
ISO 42001
8.2 - Operational planning and control
NIST AI RMF
MANAGE 4.1 - Post-deployment AI risks are monitored and managed
OWASP LLM Top 10
LLM10:2025 - Unbounded Consumption

Frequently Asked Questions

What is CVE-2026-55435?

Coder's AI Bridge proxy — the component that brokers calls to LLM providers on behalf of users — checks API key format, expiry, and secret but never checks whether the account has been suspended, so a suspended employee's still-valid token keeps working against LLM proxy endpoints. This matters for any organization running self-hosted Coder (5,435 downstream dependents) as an AI-enabled dev platform: an offboarded or disciplined user can keep consuming paid provider quota billed to the deployment, and if injected MCP tools are enabled, can keep invoking those tools, for as long as the token remains unexpired — potentially months. There is no public exploit or scanner template and it isn't in CISA KEV, and the CVSS 5.4 rating (PR:L, C:L/I:L/A:N) reflects that abuse requires an already-issued long-lived key rather than a broadly exploitable remote flaw, so this is an access-hygiene gap rather than an active-exploitation emergency. Patch to Coder v2.34.2, v2.33.8, or v2.32.7 (AI Bridge shipped in v2.30.0; the 2.29 ESR line is unaffected), and until patched, immediately revoke API keys for any suspended user via DELETE /api/v2/users/{user}/keys — suspension alone does not do this. Audit LLM provider billing and AI Bridge access logs for anomalous activity tied to accounts suspended in recent months.

Is CVE-2026-55435 actively exploited?

No confirmed active exploitation of CVE-2026-55435 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-55435?

Patch immediately: upgrade to Coder v2.34.2 (2.34.x line), v2.33.8 (2.33.x line), or v2.32.7 (2.32.x line) — all three fix AI Bridge authorization to reject non-active users, matching the standard API key middleware behavior. Coder v2.29 ESR is not affected and requires no action for this issue. Until patched, treat account suspension as incomplete: whenever suspending a user, immediately run DELETE /api/v2/users/{user}/keys to revoke their API keys — this is the documented workaround and the only way to close the gap pre-patch. For detection, audit AI Bridge/LLM proxy access logs for API key usage attributed to accounts with a suspended status, and cross-reference LLM provider billing/usage dashboards for anomalous consumption after known suspension dates. Going forward, automate key revocation as part of the offboarding/suspension workflow instead of relying on a manual step, and consider shortening API key TTLs for accounts with AI Bridge access.

What systems are affected by CVE-2026-55435?

This vulnerability affects the following AI/ML architecture patterns: agent frameworks, LLM API gateways/proxies.

What is the CVSS score for CVE-2026-55435?

CVE-2026-55435 has a CVSS v3.1 base score of 5.4 (MEDIUM). The EPSS exploitation probability is 0.32%.

What is the AI security impact?

Affected AI Architectures

agent frameworksLLM API gateways/proxies

MITRE ATLAS Techniques

AML.T0012 Valid Accounts
AML.T0034 Cost Harvesting
AML.T0053 AI Agent Tool Invocation
AML.T0096 AI Service API

Compliance Controls Affected

EU AI Act: Article 15
ISO 42001: 8.2
NIST AI RMF: MANAGE 4.1
OWASP LLM Top 10: LLM10:2025

What are the technical details?

Original Advisory

### Summary AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. > **Note:** Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. ### Impact A suspended user with a previously issued long-lived token could continue calling AI Bridge LLM proxy endpoints, consuming paid provider resources billed to the deployment and, if injected MCP tools are enabled, invoking those tools. Access persists until the token expires, which may be months after suspension. ### Patches The fix makes AI Bridge authorization reject non-active users like the standard API key middleware. AI Bridge was introduced in v2.30.0. The v2.29 ESR line is not affected. The fix is available in the following releases: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | ### Workarounds On suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`. ### Resources - Fix: #26173 ### Credits Coder would like to thank Anthropic's Security Team (ANT-2026-22446) for independently disclosing this issue!

Exploitation Scenario

An organization suspends a developer's Coder account after a policy violation or during offboarding, revoking their console/UI login. That developer, however, generated a long-lived AI Bridge API key weeks earlier while still active. Because Server.IsAuthorized in coderd/aibridgedserver checks key format, expiry, and secret but never account status, the suspended developer's key continues to authenticate successfully against AI Bridge's LLM proxy endpoints. They — or anyone who obtained the leaked token — keep issuing LLM calls billed to the organization's provider account, and if the deployment has injected MCP tools enabled on AI Bridge, they can also invoke those tools, potentially reaching internal systems the tools are wired to, all without triggering any access-revocation alert since the token itself is still cryptographically 'valid.' This persists until the token's original expiry, which the advisory notes may be months after the suspension took effect.

Weaknesses (CWE)

CWE-863 — Incorrect Authorization: The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

  • [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
  • [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Timeline

Published
July 6, 2026
Last Modified
July 9, 2026
First Seen
July 7, 2026

Related Vulnerabilities