{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/coolify--4.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:coollabsio:coolify:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-100746"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Coolify (\u003c= 4.1.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["coollabsio"],"content_html":"\u003cp\u003eCVE-2026-100746 identifies a critical missing authentication vulnerability in Coolify versions up to and including 4.1.0. The vulnerability resides within the GitHub App Setup Handler, specifically affecting the \u003ccode\u003eGithub::redirect\u003c/code\u003e function located in \u003ccode\u003e/webhooks/source/github/redirect\u003c/code\u003e. An attacker can manipulate the \u003ccode\u003estate\u003c/code\u003e argument within the GitHub authentication redirect flow to bypass authentication mechanisms entirely. Given that public proof-of-concept exploit material is available, this vulnerability poses an immediate risk of unauthorized access to self-hosted Coolify instances. Defenders should treat this as a high-priority update task, as exploitation is performed remotely without requiring existing credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to bypass authentication controls, potentially gaining administrative control over the Coolify instance. This could lead to full system compromise, deployment of malicious containers, and unauthorized access to managed infrastructure. All users running Coolify 4.1.0 or earlier are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Coolify instances to version 4.1.1 or later immediately to patch CVE-2026-100746.\u003c/li\u003e\n\u003cli\u003eReview web access logs for anomalous POST or GET requests to the endpoint \u003ccode\u003e/webhooks/source/github/redirect\u003c/code\u003e where the \u003ccode\u003estate\u003c/code\u003e parameter appears unusually formatted or is used to facilitate unexpected redirection.\u003c/li\u003e\n\u003cli\u003eVerify that any Coolify instance exposed to the internet is restricted by network-level controls (e.g., VPN or IP allowlisting) while the upgrade process is underway.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-27T05:03:58Z","date_published":"2026-09-27T05:03:58Z","id":"https://feed.craftedsignal.io/briefs/2026-09-coolify-auth-bypass/","summary":"An unauthenticated remote code execution vulnerability (CVE-2026-100746) in Coolify versions 4.1.0 and earlier allows attackers to bypass authentication via the GitHub App setup flow.","title":"Authentication Bypass in Coolify GitHub App Setup Handler","url":"https://feed.craftedsignal.io/briefs/2026-09-coolify-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Coolify (\u003c= 4.1.0)","version":"https://jsonfeed.org/version/1.1"}