


Perceptive Security
SOC/SIEM Consultancy

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes…
Published:
6 juli 2026 om 22:00:00
Alert date:
7 juli 2026 om 14:06:37
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Cloud & Virtualization
CVE-2026-34048 affects Coolify, an open-source self-hostable server and application management tool. Prior to version 4.0.0-beta.471, terminal WebSocket bootstrap routes only validated authentication but did not enforce proper authorization controls. This flaw allowed low-privileged team members to connect to terminal routes and execute arbitrary commands on team servers. The vulnerability represents a broken access control issue where authentication and authorization were conflated. The impact is significant as it could allow privilege escalation within a team environment. The issue has been patched in Coolify version 4.0.0-beta.471, with the fix available via a specific commit to the main repository.
Technical details
Mitigation steps:
Affected products:
Coolify
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-34048
https://github.com/coollabsio/coolify/commit/847166a3f89b7c80972fa0d2e5c754976f95b6ad
https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471
https://github.com/coollabsio/coolify/security/advisories/GHSA-mw6q-2hmg-mhxv
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
