CVE-2026-34171: Coolify: Account takeover via CSRF-able GET endpoint that resets password to attacker-known value
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GET /invitations/{uuid} endpoint can perform a state-changing password reset using an attacker-known invitation UUID, allowing an attacker who can cause a victim to visit the crafted invitation URL to reset the victim account password to a predictable value. This issue is fixed in version 4.0.0-beta.471.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Coolifyto a version that resolves this vulnerability.Fixed in 4.0.0-beta.471
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34171?
The severity of CVE-2026-34171 is rated as high with a score of 8.
What vulnerability does CVE-2026-34171 describe?
CVE-2026-34171 describes an account takeover risk via a CSRF-able GET endpoint allowing password resets to an attacker-known value.
How do I fix CVE-2026-34171?
To fix CVE-2026-34171, upgrade Coolify to version 4.0.0-beta.471 or later.
What are the consequences of exploiting CVE-2026-34171?
Exploiting CVE-2026-34171 could allow an attacker to take over a user's account by resetting the password.
Which software is affected by CVE-2026-34171?
CVE-2026-34171 affects the Coolify software prior to version 4.0.0-beta.471.