Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect to terminal routes and execute commands on team servers. This issue is fixed in version 4.0.0-beta.471.
Published: 2026-07-07
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check on Coolify’s terminal websocket bootstrap routes enables a user who has only low‑privilege team access to connect to the terminal service and execute arbitrary commands on team servers. Because only authentication is verified, the attacker can bypass intended role constraints and run code on the backend system, exposing all confidential data and potentially compromising the integrity and availability of the infrastructure managed by Coolify.

Affected Systems

Coolify by Coollabs.io, all versions preceding 4.0.0‑beta.471. The vulnerability exists in the terminal websocket bootstrap component of the application and is addressed in the 4.0.0‑beta.471 release and later. Systems that expose terminal websockets without a proper terminal authorization check are within scope.

Risk and Exploitability

The CVSS score of 9.9 indicates critical severity. The EPSS score of < 1% reflects a very low but non‑zero probability of exploitation, while the absence of a KEV listing suggests no publicly known exploits yet. The likely attack vector is via the web interface and requires only authenticated access with low‑privilege credentials. Once connected, the attacker can run arbitrary commands on the server, representing a major threat to the confidentiality, integrity, and availability of the infrastructure.

Generated by OpenCVE AI on July 26, 2026 at 19:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Coolify to version 4.0.0‑beta.471 or later to enforce proper terminal authorization (CWE‑285 and CWE‑862).
  • Re‑configure Coolify RBAC so that only privileged roles are allowed to access terminal routes and deploy the changes after the upgrade.
  • If an immediate update is not possible, temporarily disable the terminal websocket endpoint for low‑privileged team members or block the route at the network layer until the patch can be applied.

Generated by OpenCVE AI on July 26, 2026 at 19:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Coollabsio
Coollabsio coolify
Vendors & Products Coollabsio
Coollabsio coolify

Tue, 07 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect to terminal routes and execute commands on team servers. This issue is fixed in version 4.0.0-beta.471.
Title Coolify: Missing authorization on terminal websocket bootstrap routes allows low-privileged members to execute commands on team servers
Weaknesses CWE-285
CWE-862
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Coollabsio Coolify
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-07T13:56:10.936Z

Reserved: 2026-03-25T15:29:04.745Z

Link: CVE-2026-34048

cve-icon Vulnrichment

Updated: 2026-07-07T13:55:57.399Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:45:03Z

Weaknesses