


Perceptive Security
SOC/SIEM Consultancy

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes…
Published:
6 juli 2026 om 22:00:00
Alert date:
7 juli 2026 om 05:04:35
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Cloud & Virtualization
CVE-2026-34048 is a vulnerability in Coolify, an open-source self-hostable server and application management tool. Prior to version 4.0.0-beta.471, the terminal WebSocket bootstrap routes only verified authentication but did not enforce proper authorization controls. This flaw allowed low-privileged team members to connect to terminal routes and execute arbitrary commands on team servers. The vulnerability represents a broken access control issue where authentication and authorization were not properly separated. The impact is significant as it enables privilege escalation within a team context, potentially compromising all servers managed by the Coolify instance. The issue has been patched in version 4.0.0-beta.471. Users are strongly advised to upgrade immediately to mitigate the risk of unauthorized command execution on managed infrastructure.
Technical details
Mitigation steps:
Affected products:
Coolify
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-34048
https://github.com/coollabsio/coolify/commit/847166a3f89b7c80972fa0d2e5c754976f95b6ad
https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471
https://github.com/coollabsio/coolify/security/advisories/GHSA-mw6q-2hmg-mhxv
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
