Impact
A missing authorization check on Coolify’s terminal websocket bootstrap routes allows a low‑privileged team member to connect to the terminal service and execute arbitrary commands on the team servers. Because only authentication is validated, the attacker can bypass intended role constraints and run code on the backend system, exposing all confidential data and potentially compromising the integrity and availability of the infrastructure managed by Coolify.
Affected Systems
Coolify by Coollabs.io, all releases prior to 4.0.0‑beta.471. The issue originates in the terminal websocket bootstrap component, which was deployed in self‑hosted installations and managed through the web interface.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity, while the EPSS score of < 1 % reflects a very low, but non‑zero, likelihood of exploitation. No known public exploits exist, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely via the web interface and requires only authenticated access with low‑privilege credentials; once connected, the attacker can run arbitrary commands, representing a major threat to confidentiality, integrity, and availability.
OpenCVE Enrichment