Impact
The vulnerability resides in Coolify’s Route‑Level Middleware, specifically the CanUpdateResource.php file. Missing authorization logic allows an attacker to modify resources remotely without proper authentication or privilege checks, as indicated by the CWE‑862 and CWE‑863 identifiers. The CVSS score of 6.9 reflects a moderate risk profile, but the presence of a published exploit elevates practical concern.
Affected Systems
The weakness affects coollabsio Coolify versions up to and including 4.1.2. Upgrading to version 4.2.0 or later applies the security fix (commit 39ae16de4248075de8c08f3259114e064b20d52d) and removes the missing authorization path. No other vendors or product lines are listed as affected.
Risk and Exploitability
The flaw can be exploited from a remote location, implying that an unauthenticated attacker may craft HTTP requests that pass through the vulnerable middleware and alter resources. Although the EPSS score is not publicly available, the published exploit indicates that attackers may use it at present. The vulnerability is not listed in the CISA KEV catalog, but the moderate CVSS score and remote attack vector suggest that should treat it as a noticeable security risk.
OpenCVE Enrichment