Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-34038: Coolify Server Management Tool: Unauthorized Remote Access
CVE-2026-34038
CVE-2026-34038
Summary
Coolify, a server management tool, had a security flaw that allowed users with permission to manage applications to access the server remotely and steal sensitive information. This issue has been fixed in version 4.0.0-beta.469, so it's essential to update to this version or later to prevent any potential risks. If you're using an earlier version, we recommend upgrading as soon as possible.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| coollabsio | coolify | < 4.0.0-beta.469 |
Original title
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application d...
Original description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows users with application write permissions to achieve remote code execution and exfiltrate sensitive environment variables through deployment logs via fields such as dockerfile_location and deployment commands. This issue is fixed in version 4.0.0-beta.469.
nvd CVSS3.1
9.9
Vulnerability type
CWE-78
OS Command Injection
Published: 6 Jul 2026 · Updated: 23 Jul 2026 · First seen: 6 Jul 2026