Product
An unauthenticated remote code execution vulnerability (CVE-2026-100746) in Coolify versions 4.1.0 and earlier allows attackers to bypass authentication via the GitHub App setup flow.