CVE-2026-86117: Coolify through 4.3.17 OAuth Account Takeover via Unverified Email Matching

Published Sep 5, 2026
·
Updated

Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers can register a victim's email address on any enabled OAuth provider to obtain authenticated sessions as that user, bypassing password requirements and two-factor authentication.

Affected Software

1 affected component
Coolify<=4.3.17

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Coolify to a version that resolves this vulnerability.

    Fixed in 4.3.17

Event History

Sep 5, 2026
CVE Published
via MITRE·09:59 AM
Data Sourced
via MITRE·09:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Coolify installations through version 4.3.17 are exposed when an OAuth provider is enabled. Accounts whose email addresses can be registered by an attacker at that provider are at risk of takeover.

2

What does an attacker need to exploit it?

The attacker does not need an existing Coolify account, password, or second factor. They need to register the victim's email address with any OAuth provider enabled by the Coolify instance and complete the OAuth sign-in flow.

3

Does two-factor authentication protect affected accounts?

No. The vulnerable OAuth callback can create an authenticated session for an existing account based only on the email address, bypassing both password requirements and two-factor authentication.

4

What configuration should be prioritized for mitigation if patching is not immediately possible?

Disable enabled OAuth providers to prevent exploitation through the affected OAuth callback flow. The provided information does not identify another workaround.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203