CVE-2026-34047: Coolify: WebSocket Endpoint Access Control Flaw Leading to Remote Code Execution
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce the expected authorization middleware, allowing an authenticated user to access terminal functionality for resources outside the authorized scope and potentially execute commands. This issue is fixed in version 4.0.0-beta.471.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Coolifyto a version that resolves this vulnerability.Fixed in 4.0.0-beta.471
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34047?
CVE-2026-34047 is rated as critical with a CVSS score of 9.9.
What issue does CVE-2026-34047 describe?
CVE-2026-34047 describes a WebSocket endpoint access control flaw in Coolify that can lead to remote code execution.
How do I fix CVE-2026-34047?
To fix CVE-2026-34047, upgrade Coolify to version 4.0.0-beta.471 or later.
Who is affected by CVE-2026-34047?
Users of Coolify prior to version 4.0.0-beta.471 are affected by CVE-2026-34047.
What can attackers do with CVE-2026-34047?
Attackers can exploit CVE-2026-34047 to gain unauthorized access to terminal functionality and execute remote code.