


Perceptive Security
SOC/SIEM Consultancy

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, log drain secret and environment va…
Published:
6 juli 2026 om 22:00:00
Alert date:
7 juli 2026 om 05:04:35
Source:
nvd.nist.gov
Web Technologies, Cloud & Virtualization, Security Tools
CVE-2026-34035 affects Coolify, an open-source self-hostable server and application management tool. Prior to version 4.0.0-beta.466, log drain secret and environment variable values were interpolated directly into shell commands without proper encoding or sanitization. This flaw allowed authenticated users to inject arbitrary commands that would be executed on the host system. The vulnerability represents a command injection risk with potential for full host compromise by any authenticated user. The issue has been patched in version 4.0.0-beta.466. A fix commit is available on GitHub along with a security advisory. Users of affected versions should upgrade immediately to mitigate the risk of authenticated command injection attacks.
Technical details
Mitigation steps:
Affected products:
Coolify
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-34035
https://github.com/coollabsio/coolify/commit/fcd574e1eb1c2f504c48e5be4a5cb6d69f8f1f55
https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.466
https://github.com/coollabsio/coolify/security/advisories/GHSA-3xm2-hqg8-4m2p
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
