Description
A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing authorization. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Published: 2026-07-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in an unspecified function within the /app/Policies/ directory of Coolify versions up to 4.1.1. By manipulating this function, an attacker can remove the required authorization checks and access protected resources, effectively bypassing the system’s authorization controls.

Affected Systems

coollabsio Coolify (including 4.1.1 and all prior releases) is affected. The issue lies in the Policy Handler component, which is used by all deployments that rely on policy-based authorization; based on the description, it is inferred that any deployment utilizing this component could be impacted.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog; however, the exploit code is publicly available, increasing the risk for unpatched installations. The flaw maps to CWE-862 (Missing Authorization) and CWE-863 (Authorization Bypass By User‑Controlled Data).

Generated by OpenCVE AI on August 1, 2026 at 11:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to the latest Coolify release that contains the fix for the Policy Handler authorization issue.
  • If an immediate upgrade is not possible, restrict access to policy modification endpoints so that only administrators can edit policies, ensuring stricter role‑based controls.
  • Continuously monitor system logs for anomalous policy changes and unauthorized access attempts, and perform manual review of any suspicious activity.

Generated by OpenCVE AI on August 1, 2026 at 11:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 12 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing authorization. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Title coollabsio Coolify Policy Policies authorization
First Time appeared Coollabsio
Coollabsio coolify
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:coollabsio:coolify:*:*:*:*:*:*:*:*
Vendors & Products Coollabsio
Coollabsio coolify
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Coollabsio Coolify
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-13T15:20:01.822Z

Reserved: 2026-07-12T05:49:07.720Z

Link: CVE-2026-15507

cve-icon Vulnrichment

Updated: 2026-07-13T15:19:57.000Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:15:03Z

Weaknesses