Junglewise Threat Intelligence

CVE-2026-34047: Coolify incorrect authorization in terminal WebSocket routes

CVE-2026-34047 · Severity: critical · CVSS 9.9 · Published 2026-07-07

Executive brief

Coolify is an open-source platform used to manage servers, applications, and databases from a single dashboard. A security flaw in the terminal management component allowed users with low-level access to bypass restrictions and gain full command-line control over managed servers. This could allow an attacker to steal sensitive data, modify infrastructure, or gain root access to the underlying host machines.

Technical details

An incorrect authorization vulnerability (CWE-863) existed in Coolify's terminal WebSocket flow. While the frontend and the main GET /terminal route enforced the 'can.access.terminal' gate (restricting access to admins and owners), the backend bootstrap endpoints POST /terminal/auth and POST /terminal/auth/ips only verified general authentication. A low-privileged 'Member' user could bypass the UI, call these endpoints to obtain a list of terminal-enabled hosts, and establish a WebSocket connection to execute commands. In some scenarios, this could be escalated to root-level remote code execution by retrieving SSH private keys or generating API tokens. The fix applies the 'can.access.terminal' middleware to the vulnerable POST routes.

Affected products

  • coollabsio Coolify < 4.0.0-beta.471

Timeline

  • 2026-03-25: patched: Fix merged into development branch via PR #9169
  • 2026-04-09: advisory: Version 4.0.0-beta.471 released
  • 2026-07-02: advisory: GitHub Security Advisory published
  • 2026-07-07: disclosed: CVE-2026-34047 published to NVD

References