Impact
Coolify’s API validation endpoints were guarded by a read‑only permission, enabling a read‑scoped API token to trigger operations that normally modify system state, such as validating cloud provider credentials and provisioning servers. This defect constitutes an authorization bypass (CWE‑863) that lets an authenticated attacker perform actions reserved for higher‑level scopes without executing arbitrary code.
Affected Systems
The flaw affects all Coolify releases before version 4.0.0‑beta.466; updating to that version or later removes the vulnerability.
Risk and Exploitability
The CVSS score of 6.5 classifies the flaw as moderate severity. The EPSS score of less than 1 % suggests that exploitation is unlikely but still possible. It is not listed in the CISA KEV catalogue. An attacker only needs a valid read‑scoped API token—potentially exposed or reused—to issue API requests that invoke state‑changing endpoints, thereby gaining unintended control over resources.
OpenCVE Enrichment