Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect to terminal routes and execute commands on team servers. This issue is fixed in version 4.0.0-beta.471.
Published: 2026-07-07
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check on Coolify’s terminal websocket bootstrap routes allows a low‑privileged team member to connect to the terminal service and execute arbitrary commands on the team servers. Because only authentication is validated, the attacker can bypass intended role constraints and run code on the backend system, exposing all confidential data and potentially compromising the integrity and availability of the infrastructure managed by Coolify.

Affected Systems

Coolify by Coollabs.io, all releases prior to 4.0.0‑beta.471. The issue originates in the terminal websocket bootstrap component, which was deployed in self‑hosted installations and managed through the web interface.

Risk and Exploitability

The CVSS score of 9.9 indicates critical severity, while the EPSS score of < 1 % reflects a very low, but non‑zero, likelihood of exploitation. No known public exploits exist, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely via the web interface and requires only authenticated access with low‑privilege credentials; once connected, the attacker can run arbitrary commands, representing a major threat to confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 1, 2026 at 17:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Coolify to version 4.0.0‑beta.471 or later to enforce proper terminal authorization.
  • Re‑configure RBAC so that only privileged roles can access terminal routes and apply the changes after the upgrade.
  • If an upgrade is not immediately possible, disable the terminal websocket endpoint for low‑privileged team members or block the route at the network layer until the patch can be applied.

Generated by OpenCVE AI on August 1, 2026 at 17:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Coollabsio
Coollabsio coolify
Vendors & Products Coollabsio
Coollabsio coolify

Tue, 07 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect to terminal routes and execute commands on team servers. This issue is fixed in version 4.0.0-beta.471.
Title Coolify: Missing authorization on terminal websocket bootstrap routes allows low-privileged members to execute commands on team servers
Weaknesses CWE-285
CWE-862
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Coollabsio Coolify
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-07T13:56:10.936Z

Reserved: 2026-03-25T15:29:04.745Z

Link: CVE-2026-34048

cve-icon Vulnrichment

Updated: 2026-07-07T13:55:57.399Z

cve-icon NVD

Status : Deferred

Published: 2026-07-07T04:17:48.417

Modified: 2026-07-07T15:16:43.953

Link: CVE-2026-34048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T18:00:12Z

Weaknesses