CVE-2026-15507: coollabsio Coolify Policy Policies authorization
Published Jul 12, 2026
·Updated
A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing authorization. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected Software
1 affected component
coollabsio Coolify<=4.1.1
Event History
Jul 12, 2026
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-15507?
CVE-2026-15507 has a medium severity rating of 6.3.
2
How do I fix CVE-2026-15507?
To fix CVE-2026-15507, update coollabsio Coolify to version 4.1.2 or later.
3
What component is affected by CVE-2026-15507?
CVE-2026-15507 affects the Policy Handler component of coollabsio Coolify.
4
What type of vulnerability is CVE-2026-15507?
CVE-2026-15507 is an authorization vulnerability that allows exploitation without proper authorization.
5
Can CVE-2026-15507 be exploited remotely?
Yes, CVE-2026-15507 can be exploited remotely by manipulating the Policy Handler.