Junglewise Threat Intelligence

CVE-2026-5302: CoolerControl coolercontrold CORS misconfiguration

CVE-2026-5302 · Severity: medium · CVSS 6.3 · Published 2026-04-08

Technologies: Coolercontrold. Vendors: Coolercontrol.

Executive brief

CoolerControl is a software suite used to monitor and control hardware cooling systems like fans and liquid coolers. A security flaw in the background service allows malicious websites to bypass browser security protections. If a user visits a compromised site while the software is running, an attacker could remotely view system data or change cooling settings, potentially leading to hardware overheating or unauthorized system access.

Technical details

A Cross-Origin Resource Sharing (CORS) misconfiguration exists in the coolercontrold API in versions prior to 4.0.0. The service implements a permissive cross-domain policy (CWE-942) that fails to properly restrict which origins can interact with the local API. An attacker can exploit this by enticing a user to visit a malicious website, which then uses the user's browser as a proxy to send unauthorized requests to the local coolercontrold service. This allows for unauthenticated data exfiltration and the execution of commands. The issue is resolved in version 4.0.0.

Affected products

  • CoolerControl coolercontrold < 4.0.0

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-08: patched: Fixed in version 4.0.0

References

Related threats