CVE-2026-30968

CRITICAL

Coral Server < 1.1.0 - Unauthenticated Message Injection or Observation via SSE Endpoint

Title source: llm
STIX 2.1

Description

Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, the SSE endpoint (/sse/v1/...) in Coral Server did not strongly validate that a connecting agent was a legitimate participant in the session. This could theoretically allow unauthorized message injection or observation. This vulnerability is fixed in 1.1.0.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0034
EPSS Percentile 26.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (1)
coralos/coral_server < 1.1.0
Published Mar 10, 2026
Tracked Since Mar 11, 2026