PT-2026-24339 · Unknown · Coral-Server

Seafraf

·

Published

2026-03-10

·

Updated

2026-03-16

·

CVE-2026-30968

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Coral Server versions prior to 1.1.0
Description Coral Server is an open collaboration infrastructure designed for communication, coordination, trust, and payments within The Internet of Agents. Before version 1.1.0, the Server Side Events (SSE) endpoint, specifically /sse/v1/..., lacked robust validation to ensure connecting agents were authorized session participants. This could potentially allow for unauthorized message injection or observation.
Recommendations Update to version 1.1.0 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-30968
GHSA-2RJ5-3PGM-XQW9

Affected Products

Coral-Server