Impact
Coolify is an open‑source, self‑hostable platform for managing servers, applications, and databases. A cross‑team IDOR flaw in the Logs component existed before version 4.0 The component resolves resources solely by UUID, ignoring the current user’s team context. The flaw permits an authenticated user to retrieve logs for applications that belong to other teams by supplying a victim application’s UUID, leading to unauthorized disclosure of potentially sensitive operational information. This weakness is known as Insecure Direct Object Reference (CWE-639).
Affected Systems
The vulnerability affects coollabsio’s Coolify platform in all releases prior to 4.0.0-beta.466. Users running older versions are at risk; the issue was fixed in the 4.0.0-beta.466 release.
Risk and Exploitability
The CVSS score of 7.7 indicates medium‑high severity. The EPSS score of <1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in the wild. Exploitation requires a legitimate, authenticated user’s account; the attacker can supply any UUID to the Logs endpoint. Successful exploitation would provide read access to logs across team boundaries, potentially revealing configuration details, secrets, or other sensitive data.
OpenCVE Enrichment