CVE-2026-55176
Received Received - Intake

Authentication Bypass in Soft Machine Workspaces

Vulnerability report for CVE-2026-55176, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINER_SHARED_SECRET as a bearer token without verifying which workspace the caller belongs to. Because that secret is set identically on every container in the Fly app and is reachable from the user-facing process environment inside each workspace, any tenant can use it to authenticate to any other tenant's workspace API. The result is cross-workspace read, write, and destructive-restore primitives reachable from any paying customer's shell. The existing per-workspace token check (workspaceTokenMatches) protects the user-facing per-workspace token path, but the shared-secret bearer path bypasses it entirely. At time of publication, there are no publicly known patches.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
soft_machine soft_machine to 0.2.247 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55176 is a critical authentication bypass in Soft Machine's workspace API. Two functions in /app/server.js, verifyContainerAuth() and authenticateWorkspaceHttp(), accept a global CONTAINER_SHARED_SECRET as a bearer token without validating the caller's workspace. This shared secret is identical across all containers and exposed in user-facing environments, allowing any tenant to authenticate to any other tenant's workspace API.

Detection Guidance

Check for unauthorized API requests using the shared CONTAINER_SHARED_SECRET in HTTP headers. Inspect logs for cross-workspace actions like file reads, writes, or restores. Look for unexpected bearer token usage in /app/server.js authentication functions.

Impact Analysis

This vulnerability allows any paying customer to access other tenants' workspaces without authorization. Attackers can read files, write arbitrary data, hijack backups, overwrite workspace contents, or tamper with bindings. Exploitation requires only a single HTTP request with the shared secret from an active workspace shell.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and access control in GDPR and HIPAA. It enables unauthorized cross-tenant data access, compromising confidentiality and integrity of sensitive information across all tenants.

Mitigation Strategies

Rotate the CONTAINER_SHARED_SECRET immediately and restrict its exposure in tenant environments. Implement per-workspace token validation in verifyContainerAuth() and authenticateWorkspaceHttp(). Disable cross-workspace API access until patches are applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55176. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart