CVE-2026-34049: Coolify: Command Injection via unsanitized MongoDB collection names in database backup
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.451 through 4.0.0-beta.470, database backup handling for MongoDB collection names did not fully validate shell metacharacters, allowing a highly privileged attacker who can configure backup inputs to inject commands. This issue is fixed in version 4.0.0-beta.471.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Coolifyto a version that resolves this vulnerability.Fixed in 4.0.0-beta.471
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34049?
CVE-2026-34049 has a low severity rating of 3.3.
What does CVE-2026-34049 allow an attacker to do?
CVE-2026-34049 allows a highly privileged attacker to perform command injection via unsanitized MongoDB collection names in database backup.
What versions of Coolify are affected by CVE-2026-34049?
Coolify versions from 4.0.0-beta.451 through 4.0.0-beta.470 are affected by CVE-2026-34049.
How can I mitigate CVE-2026-34049?
To mitigate CVE-2026-34049, ensure proper validation of shell metacharacters in MongoDB collection names.
Is there a fix available for CVE-2026-34049?
Yes, an update has been made to address the vulnerability in affected versions of Coolify.