Junglewise Threat Intelligence

CVE-2026-34037: Coolify cross-tenant resource cloning in ResourceOperations.php

CVE-2026-34037 · Severity: critical · CVSS 9.9 · Published 2026-07-07

Executive brief

Coolify is an open-source platform used to manage and deploy servers, applications, and databases. A security flaw in the resource management system allows an authenticated user to bypass team boundaries and clone or move resources (like applications or databases) onto servers owned by other teams. This could lead to unauthorized access to another team's infrastructure, potential data exposure, and the ability to run arbitrary code on their servers.

Technical details

The vulnerability exists in the cloneTo() and moveTo() Livewire actions within ResourceOperations.php. While the application authorizes the source resource, it resolves destination resources (servers or environments) using unscoped Eloquent lookups (e.g., StandaloneDocker::find($destination_id)) without verifying that the destination belongs to the current user's team. Furthermore, the StandaloneDockerPolicy::update() method was found to return 'true' unconditionally, bypassing intended authorization checks. An attacker can exploit this by intercepting the Livewire POST request and replacing the destination ID with a sequential integer corresponding to another team's server. This allows for cross-tenant resource deployment and potential infrastructure takeover. The issue is fixed in version 4.0.0-beta.464 by implementing team-scoped lookups.

Affected products

  • coollabsio Coolify < 4.0.0-beta.464

Timeline

  • 2026-02-25: patched: Fix commit authored
  • 2026-03-09: advisory: Release v4.0.0-beta.464 published
  • 2026-07-02: disclosed: Security advisory published on GitHub
  • 2026-07-07: advisory: NVD publication date

References