Impact
The vulnerability lies in the Settings/Updates Livewire component of Coolify, which fails to verify whether a user is an instance administrator during its mount operation. This omission allows any authenticated user with lesser privileges to access the Updates settings page, modify auto‑update preferences, or trigger update checks, thereby allowing unauthorized configuration changes. The weakness is a missing authorization check, mapped to CWE‑862.
Affected Systems
Coolify, a self‑hostable server management platform provided by coollabsio. Versions prior to 4.0.0‑beta.471 are affected; the issue is resolved in 4.0.0‑beta.471 and later releases.
Risk and Exploitability
The CVSS score of 6.5 places this issue in the Medium severity range, indicating that exploitation could provide a significant advantage to an attacker. The EPSS score is <1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit this accessible to any authenticated user; no additional conditions are specified in the description.
OpenCVE Enrichment