CVE-2026-34594: Coolify: Authenticated Remote Code Execution via Command Injection in Destination Network Management
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, an authenticated command injection vulnerability in the Destination Network Management functionality allows users with destination management permissions to execute arbitrary commands as root on managed servers. The "network" parameter is passed directly to shell commands without proper sanitization, enabling full remote code execution on the host system. This vulnerability is fixed in 4.0.0-beta.471.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Coolifyto a version that resolves this vulnerability.Fixed in 4.0.0-beta.471
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34594?
CVE-2026-34594 has a high severity rating of 8.8.
How do I fix CVE-2026-34594?
To fix CVE-2026-34594, update Coolify to version 4.0.0-beta.471 or later.
What type of vulnerability is CVE-2026-34594?
CVE-2026-34594 is an authenticated remote code execution vulnerability due to command injection.
Who is affected by CVE-2026-34594?
Users with destination management permissions in Coolify versions prior to 4.0.0-beta.471 are affected by CVE-2026-34594.
What can be exploited through CVE-2026-34594?
CVE-2026-34594 allows attackers to execute arbitrary commands on the server via the Destination Network Management functionality.