Junglewise Threat Intelligence

CVE-2026-15507: coollabsio Coolify missing authorization in Policy Handler

CVE-2026-15507 · Severity: medium · CVSS 6.3 · Published 2026-07-12

Technologies: Coollabs Coolify. Vendors: Coollabs.

Executive brief

Coolify, an open-source platform for managing self-hosted applications and databases, contains a security flaw in its authorization system. This vulnerability allows an authenticated user to bypass intended access controls and potentially view or modify resources they should not have permission to access. This could lead to unauthorized changes to server configurations or exposure of internal application data.

Technical details

A missing authorization vulnerability (CWE-862/CWE-863) exists in coollabsio Coolify versions up to 4.1.1 within the Policy Handler component, specifically affecting files in the /app/Policies/ directory. The flaw allows a remote attacker with low-level authenticated privileges to perform unauthorized actions by manipulating requests to the application's policy enforcement logic. While the specific function is not identified in the advisory, the root cause is a failure to properly validate user permissions before executing resource-related operations. A public exploit has been reported, increasing the risk of exploitation in environments where multi-tenancy or granular access control is required.

Affected products

  • coollabsio Coolify Up to 4.1.1

Timeline

  • 2026-07-12: disclosed: Initial disclosure via VulDB and NVD
  • 2026-07-12: advisory: NVD publication date

References