Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-86117: Coolify lets attackers log in as users via email match
CVE-2026-86117 · published today
Summary
Coolify versions up to 4.3.17 can sign a person in just because the email address they use with a third‑party login matches an existing account. An attacker could create an account on a linked service using a victim’s email and then gain access to that victim’s Coolify account without needing the password or two‑factor code. To protect yourself, update Coolify to the latest version that requires proper verification of third‑party logins, and review your OAuth configuration to ensure only trusted providers are enabled.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| coollabsio | coolify | <= 4.3.17 |
Original advisory text
Coolify through 4.3.17 OAuth Account Takeover via Unverified Email Matching
Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers can register a victim's email address on any enabled OAuth provider to obtain authenticated sessions as that user, bypassing password requirements and two-factor authentication.
References
- https://github.com/coollabsio/coolify product
- https://github.com/coollabsio/coolify/blob/v4.3.17/app/Http/Controllers/OauthCon... technical-description
- https://github.com/coollabsio/coolify/blob/v4.3.17/routes/web.php technical-description
- https://github.com/geo-chen/oss/blob/main/coolify.md technical-description
- https://www.vulncheck.com/advisories/coolify-through-4.3.17-oauth-account-takeov... third-party-advisory
Severity
9.2
Critical
CVSS 3.1: 8.1 (NVD)
CVSS 4.0: 9.2 (NVD)
Type
CWE-287Improper Authentication
Timeline
Published5 Sep 2026
Updated5 Sep 2026
First seen5 Sep 2026
Monitor software like this
Free during beta