Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-34037: Coolify: Cloning resources into other teams' accounts

CVE-2026-34037 CVE-2026-34037
Summary

A previous version of Coolify allowed authorized users to copy resources into accounts they shouldn't have access to. This means they could potentially access or modify sensitive information. Update to the latest version of Coolify to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
coollabsio coolify < 4.0.0-beta.464
Original title
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the s...
Original description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but resolves destination resources with unscoped Eloquent lookups, allowing an authenticated user to clone resources into destinations owned by other teams and access cross-tenant resources. This issue is fixed in version 4.0.0-beta.464.
mitre CVSS3.1 9.9
Vulnerability type
CWE-639 Authorization Bypass Through User-Controlled Key
Published: 7 Jul 2026 · Updated: 20 Jul 2026 · First seen: 7 Jul 2026