Coder's AI Bridge proxy — the component that brokers calls to LLM providers on behalf of users — checks API key format, expiry, and secret but never checks whether the account has been suspended, so a suspended employee's still-valid token keeps working against LLM proxy endpoints. This matters for any organization running self-hosted Coder (5,435 downstream dependents) as an AI-enabled dev platform: an offboarded or disciplined user can keep consuming paid provider quota billed to the deployment, and if injected MCP tools are enabled, can keep invoking those tools, for as long as the token remains unexpired — potentially months. There is no public exploit or scanner template and it isn't in CISA KEV, and the CVSS 5.4 rating (PR:L, C:L/I:L/A:N) reflects that abuse requires an already-issued long-lived key rather than a broadly exploitable remote flaw, so this is an access-hygiene gap rather than an active-exploitation emergency. Patch to Coder v2.34.2, v2.33.8, or v2.32.7 (AI Bridge shipped in v2.30.0; the 2.29 ESR line is unaffected), and until patched, immediately revoke API keys for any suspended user via DELETE /api/v2/users/{user}/keys — suspension alone does not do this. Audit LLM provider billing and AI Bridge access logs for anomalous activity tied to accounts suspended in recent months.
What is the risk?
Medium severity (CVSS 5.4) with low practical exploitability: PR:L means an attacker needs an already-provisioned, unexpired API key issued before suspension — this is not a remotely exploitable pre-auth flaw, and no public exploit or Nuclei template exists. Impact scope depends heavily on org-specific token lifetimes and whether injected MCP tools are enabled on AI Bridge; deployments with long-lived tokens and MCP tool access face materially higher exposure since abuse extends beyond LLM cost consumption to potential tool invocation. Confidentiality and integrity impact are both rated Low (C:L/I:L) and availability is unaffected (A:N), consistent with unauthorized-but-bounded API access rather than data exfiltration or system compromise. Risk rises with headcount turnover velocity — the more frequently users are suspended (terminations, policy violations, contractor rotations), the larger the cumulative exposure window across an organization.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Anthropic Python | go | >= 2.34.0, < 2.34.2 | 2.34.2 |
Do you use Anthropic Python? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
Patch immediately: upgrade to Coder v2.34.2 (2.34.x line), v2.33.8 (2.33.x line), or v2.32.7 (2.32.x line) — all three fix AI Bridge authorization to reject non-active users, matching the standard API key middleware behavior. Coder v2.29 ESR is not affected and requires no action for this issue. Until patched, treat account suspension as incomplete: whenever suspending a user, immediately run DELETE /api/v2/users/{user}/keys to revoke their API keys — this is the documented workaround and the only way to close the gap pre-patch. For detection, audit AI Bridge/LLM proxy access logs for API key usage attributed to accounts with a suspended status, and cross-reference LLM provider billing/usage dashboards for anomalous consumption after known suspension dates. Going forward, automate key revocation as part of the offboarding/suspension workflow instead of relying on a manual step, and consider shortening API key TTLs for accounts with AI Bridge access.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-55435?
Coder's AI Bridge proxy — the component that brokers calls to LLM providers on behalf of users — checks API key format, expiry, and secret but never checks whether the account has been suspended, so a suspended employee's still-valid token keeps working against LLM proxy endpoints. This matters for any organization running self-hosted Coder (5,435 downstream dependents) as an AI-enabled dev platform: an offboarded or disciplined user can keep consuming paid provider quota billed to the deployment, and if injected MCP tools are enabled, can keep invoking those tools, for as long as the token remains unexpired — potentially months. There is no public exploit or scanner template and it isn't in CISA KEV, and the CVSS 5.4 rating (PR:L, C:L/I:L/A:N) reflects that abuse requires an already-issued long-lived key rather than a broadly exploitable remote flaw, so this is an access-hygiene gap rather than an active-exploitation emergency. Patch to Coder v2.34.2, v2.33.8, or v2.32.7 (AI Bridge shipped in v2.30.0; the 2.29 ESR line is unaffected), and until patched, immediately revoke API keys for any suspended user via DELETE /api/v2/users/{user}/keys — suspension alone does not do this. Audit LLM provider billing and AI Bridge access logs for anomalous activity tied to accounts suspended in recent months.
Is CVE-2026-55435 actively exploited?
No confirmed active exploitation of CVE-2026-55435 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-55435?
Patch immediately: upgrade to Coder v2.34.2 (2.34.x line), v2.33.8 (2.33.x line), or v2.32.7 (2.32.x line) — all three fix AI Bridge authorization to reject non-active users, matching the standard API key middleware behavior. Coder v2.29 ESR is not affected and requires no action for this issue. Until patched, treat account suspension as incomplete: whenever suspending a user, immediately run DELETE /api/v2/users/{user}/keys to revoke their API keys — this is the documented workaround and the only way to close the gap pre-patch. For detection, audit AI Bridge/LLM proxy access logs for API key usage attributed to accounts with a suspended status, and cross-reference LLM provider billing/usage dashboards for anomalous consumption after known suspension dates. Going forward, automate key revocation as part of the offboarding/suspension workflow instead of relying on a manual step, and consider shortening API key TTLs for accounts with AI Bridge access.
What systems are affected by CVE-2026-55435?
This vulnerability affects the following AI/ML architecture patterns: agent frameworks, LLM API gateways/proxies.
What is the CVSS score for CVE-2026-55435?
CVE-2026-55435 has a CVSS v3.1 base score of 5.4 (MEDIUM). The EPSS exploitation probability is 0.32%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0012 Valid Accounts AML.T0034 Cost Harvesting AML.T0053 AI Agent Tool Invocation AML.T0096 AI Service API Compliance Controls Affected
What are the technical details?
Original Advisory
### Summary AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. > **Note:** Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. ### Impact A suspended user with a previously issued long-lived token could continue calling AI Bridge LLM proxy endpoints, consuming paid provider resources billed to the deployment and, if injected MCP tools are enabled, invoking those tools. Access persists until the token expires, which may be months after suspension. ### Patches The fix makes AI Bridge authorization reject non-active users like the standard API key middleware. AI Bridge was introduced in v2.30.0. The v2.29 ESR line is not affected. The fix is available in the following releases: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | ### Workarounds On suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`. ### Resources - Fix: #26173 ### Credits Coder would like to thank Anthropic's Security Team (ANT-2026-22446) for independently disclosing this issue!
Exploitation Scenario
An organization suspends a developer's Coder account after a policy violation or during offboarding, revoking their console/UI login. That developer, however, generated a long-lived AI Bridge API key weeks earlier while still active. Because Server.IsAuthorized in coderd/aibridgedserver checks key format, expiry, and secret but never account status, the suspended developer's key continues to authenticate successfully against AI Bridge's LLM proxy endpoints. They — or anyone who obtained the leaked token — keep issuing LLM calls billed to the organization's provider account, and if the deployment has injected MCP tools enabled on AI Bridge, they can also invoke those tools, potentially reaching internal systems the tools are wired to, all without triggering any access-revocation alert since the token itself is still cryptographically 'valid.' This persists until the token's original expiry, which the advisory notes may be months after the suspension took effect.
Weaknesses (CWE)
CWE-863 — Incorrect Authorization: The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
- [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
- [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N References
Timeline
Related Vulnerabilities
CVE-2026-27775 8.8 Gitea: cached permission check allows repo takeover
Same package: anthropic CVE-2026-54449 8.8 LangBot: RCE via arbitrary STDIO MCP command
Same package: anthropic CVE-2026-7574 8.7 Claude Desktop: VM integrity bypass enables RCE
Same package: anthropic CVE-2026-55429 8.7 Coder: cross-workspace agent hijack via app ID reuse
Same package: anthropic CVE-2026-67428 8.5 Flyto2 Core: SSRF via unvalidated URLs in agent tools
Same package: anthropic