CVE-2026-30970 describes a critical authentication bypass vulnerability in Coral Server versions prior to 1.1.0, specifically affecting the /api/v1/sessions endpoint. This flaw allows unauthenticated attackers to create agent sessions and trigger resource-intensive initialization operations. With a CVSS score of 9.1, the vulnerability is remotely exploitable without authentication or user interaction, potentially leading to unauthorized access or a denial-of-service condition by exhausting system resources. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability. The issue is resolved in Coral Server version 1.1.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.0CPE matchmatch criteria | cpe:2.3:a:coralos:coral_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.