← Back to browse · API

CVE-2026-34048

Severity
CRITICAL
CVSS
9.9
EPSS
0.00576
Risk score
39.8
CISA KEV
No
PoC
No
Published
2026-07-07
Modified
2026-07-07
First seen
2026-08-07
Aliases
EUVD-2026-41995
Products
coollabsio:coolify < 4.0.0-beta.471
Sources
euvd EUVD-2026-41995

Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect to terminal routes and execute commands on team servers. This issue is fixed in version 4.0.0-beta.471.

References