Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, Coral Server did not enforce strong authentication between agents and the server within an active session. This could allow an attacker who obtained or predicted a session identifier to impersonate an agent or join an existing session. This vulnerability is fixed in 1.1.0.
References
| Link | Resource |
|---|---|
| https://github.com/Coral-Protocol/coral-server/releases/tag/v1.1.0 | Release Notes |
| https://github.com/Coral-Protocol/coral-server/security/advisories/GHSA-ccx7-7wv9-c55x | Vendor Advisory |
Configurations
History
13 Mar 2026, 19:51
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Coralos
Coralos coral Server |
|
| CPE | cpe:2.3:a:coralos:coral_server:*:*:*:*:*:*:*:* | |
| References | () https://github.com/Coral-Protocol/coral-server/releases/tag/v1.1.0 - Release Notes | |
| References | () https://github.com/Coral-Protocol/coral-server/security/advisories/GHSA-ccx7-7wv9-c55x - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
11 Mar 2026, 13:53
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
10 Mar 2026, 18:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-10 18:18
Updated : 2026-03-13 19:51
NVD link : CVE-2026-30969
Mitre link : CVE-2026-30969
CVE.ORG link : CVE-2026-30969
JSON object : View
Products Affected
coralos
- coral_server
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
