Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-57498: Coolify prior to 4.0.0-beta.474 allows unauthorized server access

CVE-2026-57498
Summary

A security issue in Coolify's web interface allows users from one team to access and deploy servers managed by another team. This is fixed in version 4.0.0-beta.474. To stay secure, ensure you're running the latest version of Coolify.

Original title
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Se...
Original description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any operation. However, multiple Livewire web UI components accept server_id and destination_uuid from URL query parameters without any team ownership validation, allowing cross-team resource deployment. This vulnerability is fixed in 4.0.0-beta.474.
nvd CVSS3.1 9.6
Vulnerability type
CWE-639 Authorization Bypass Through User-Controlled Key
CWE-862 Missing Authorization
Published: 29 Jun 2026 · Updated: 20 Jul 2026 · First seen: 29 Jun 2026