Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-34594: Coolify: Authenticated Command Injection in Network Management

CVE-2026-34594
Summary

Coolify's network management feature had a security flaw that allowed authorized users to execute commands on managed servers as if they were the server administrator. This could be exploited to take control of the server. The issue has been fixed in version 4.0.0-beta.471.

Original title
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, an authenticated command injection vulnerability in the Destination Netw...
Original description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, an authenticated command injection vulnerability in the Destination Network Management functionality allows users with destination management permissions to execute arbitrary commands as root on managed servers. The "network" parameter is passed directly to shell commands without proper sanitization, enabling full remote code execution on the host system. This vulnerability is fixed in 4.0.0-beta.471.
nvd CVSS3.1 8.8
Vulnerability type
CWE-78 OS Command Injection
Published: 29 Jun 2026 · Updated: 23 Jul 2026 · First seen: 29 Jun 2026