Two flaws in Coder's OIDC login chained into account takeover: email-based user matching fell back to linking by email without checking for an existing link to a different IdP subject and the email_verified claim was only enforced when present as a boolean false so an absent or non-boolean claim was treated as verified.
An attacker who could authenticate at the configured OIDC provider with an email matching a victim's Coder account could log in as that victim and gain full access to their workspaces, templates and resources. This required OIDC authentication, attacker control of a matching email at the IdP and a victim account not yet linked to a different IdP subject.
The fix restricts the email fallback to first-time and legacy linking and defaults email_verified to false when the claim is absent or of an unexpected type.
The fix was backported to all supported release lines:
| Release line | Patched version | |---|---| | 2.34 | v2.34.2 | | 2.33 | v2.33.8 | | 2.32 | v2.32.7 | | 2.29 (ESR) | v2.29.17 |
Configure the OIDC provider to disallow self-registration or to require email verification before issuing tokens.
Coder would like to thank Anthropic's Security Team (ANT-2026-22450) for independently disclosing this issue!
{
"severity": "HIGH",
"nvd_published_at": null,
"github_reviewed": true,
"cwe_ids": [
"CWE-287",
"CWE-289"
],
"github_reviewed_at": "2026-07-06T20:52:13Z"
}