CVE-2026-30969 Details
Description
Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, Coral Server did not enforce strong authentication between agents and the server within an active session. This could allow an attacker who obtained or predicted a session identifier to impersonate an agent or join an existing session. This vulnerability is fixed in 1.1.0.
A vulnerability in Coral Server prior to version 1.1.0 allowed for weak authentication between agents and the server during active sessions. This flaw could be exploited by an attacker who obtained or predicted a session identifier, enabling them to impersonate an agent or join an existing session.
Users can upgrade to Coral Server version 1.1.0 or later to address this vulnerability. The update introduces per-agent session secrets that are required for communication between agents and the server, enhancing authentication security.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Coral-Protocol/coral-server/releases/tag/v1.1.0 | [email protected] | Release Notes |
| https://github.com/Coral-Protocol/coral-server/security/advisories/GHSA-ccx7-7wv9-c55x | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| coralos coral server | < 1.1.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 13, 2026 | Initial Analysis | [email protected] |
| Mar 10, 2026 | New CVE Received | [email protected] |