{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acoollabscoolify/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:coollabs:coolify:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-100744"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Coolify (\u003c= 4.1.2)"],"_cs_severities":["high"],"_cs_tags":["web-application","vulnerability","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["Coollabs"],"content_html":"\u003cp\u003eCoolify versions up to 4.1.2 are susceptible to a security flaw identified as CVE-2026-100744, residing within the Route-Level Middleware component. Specifically, the vulnerability exists in the \u003ccode\u003eapp/Http/Middleware/CanUpdateResource.php\u003c/code\u003e file, which fails to properly enforce authorization checks when handling requests. This flaw enables a remote, unauthenticated attacker to manipulate resource access, potentially resulting in unauthorized modifications to infrastructure or application configurations managed by Coolify. Publicly available exploit material indicates that this vulnerability is actively tracked, increasing the risk of exploitation. Defenders should prioritize updating to Coolify version 4.2.0, which includes the necessary patch (commit 39ae16de4248075de8c08f3259114e064b20d52d) to resolve the missing authorization logic.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote actors to bypass security controls and perform unauthorized operations within the Coolify dashboard. This can lead to full compromise of managed infrastructure, unauthorized deployment of malicious services, or the manipulation of application settings, posing a critical risk to environments relying on Coolify for container orchestration and self-hosted application management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Coolify to version 4.2.0 or later to remediate CVE-2026-100744.\u003c/li\u003e\n\u003cli\u003eAudit application logs for abnormal requests directed at resource-management endpoints, particularly those attempting to trigger update middleware.\u003c/li\u003e\n\u003cli\u003eReview access control configurations for all managed resources to ensure unintended modifications have not been performed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-27T03:03:47Z","date_published":"2026-09-27T03:03:47Z","id":"https://feed.craftedsignal.io/briefs/2026-09-coolify-missing-auth/","summary":"Coolify versions 4.1.2 and prior contain a missing authorization vulnerability in the Route-Level Middleware component, allowing remote attackers to perform unauthorized resource updates.","title":"Missing Authorization Vulnerability in Coolify","url":"https://feed.craftedsignal.io/briefs/2026-09-coolify-missing-auth/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:coollabs:coolify:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}