Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-34048: Coolify: Low-Privileged Users Can Run Server Commands
CVE-2026-34048
CVE-2026-34048
Summary
A security issue in Coolify's terminal feature allows team members with limited access to run server commands on other team members' servers. This could lead to unintended changes or data loss. To fix this, update Coolify to version 4.0.0-beta.471 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| coollabsio | coolify | < 4.0.0-beta.471 |
Original title
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not...
Original description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect to terminal routes and execute commands on team servers. This issue is fixed in version 4.0.0-beta.471.
mitre CVSS3.1
9.9
Vulnerability type
CWE-285
Improper Authorization
CWE-862
Missing Authorization
Published: 7 Jul 2026 · Updated: 23 Jul 2026 · First seen: 7 Jul 2026