Junglewise Threat Intelligence

CVE-2026-34592: Coolabsio Coolify IDOR in server and project lookups

CVE-2026-34592 · Severity: high · CVSS 7.7 · Published 2026-06-29

Technologies: Coollabs Coolify. Vendors: Coollabs.

Executive brief

Coolify, an open-source tool used to manage servers and databases, contains a security flaw that allows users to view resources belonging to other teams. By simply changing an ID number in a request, an authenticated user can access private server and project details they are not authorized to see. This could lead to the exposure of sensitive infrastructure information and SSH keys, potentially compromising the security of the entire managed environment.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in Coolify due to improper authorization checks during resource lookups. Specifically, server and project queries are not scoped to the authenticated user's team, allowing a user with low privileges to access data from other teams by manipulating resource IDs (CWE-639). An attacker can exploit this over the network to view sensitive infrastructure details and SSH keys. The vulnerability is present in versions prior to 4.0.0-beta.471 and has been addressed by implementing team-level authorization checks on all resource lookup endpoints.

Affected products

  • coollabsio Coolify < 4.0.0-beta.471

Timeline

  • 2026-06-25: advisory: GitHub Security Advisory published
  • 2026-06-29: disclosed: CVE published to NVD
  • 2026-06-29: patched: Fixed in version 4.0.0-beta.471

References

Related threats