Junglewise Threat Intelligence

CVE-2026-34050: Coolify missing authorization in Settings/Updates component

CVE-2026-34050 · Severity: medium · CVSS 6.5 · Published 2026-07-06

Technologies: Coollabs Coolify. Vendors: Coollabs.

Executive brief

Coolify is an open-source platform used to manage and automate the deployment of servers, applications, and databases. A security flaw allowed standard users to access administrative update settings that should have been restricted. This could allow unauthorized individuals to change how the system updates itself or trigger manual update checks, potentially affecting the stability of the management platform.

Technical details

A missing authorization check (CWE-862) exists in the 'mount' method of the Settings/Updates Livewire component in Coolify. While other administrative components verify the 'isInstanceAdmin' status, this specific component failed to do so, allowing any authenticated user to reach the updates configuration page. An attacker with low-level privileges can exploit this over the network to modify auto-update configurations or initiate update processes. The vulnerability was addressed in version 4.0.0-beta.471 by adding the necessary authorization check and redirecting unauthorized users to the dashboard.

Affected products

  • coollabsio Coolify < 4.0.0-beta.471

Timeline

  • 2026-04-05: patched: Fix merged in pull request 9206
  • 2026-07-02: advisory: GitHub Security Advisory published
  • 2026-07-06: disclosed: CVE published to NVD

References

Related threats