<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Coolify (&lt;= 4.1.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/coolify--4.1.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 27 Sep 2026 03:03:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/coolify--4.1.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Missing Authorization Vulnerability in Coolify</title><link>https://feed.craftedsignal.io/briefs/2026-09-coolify-missing-auth/</link><pubDate>Sun, 27 Sep 2026 03:03:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-coolify-missing-auth/</guid><description>Coolify versions 4.1.2 and prior contain a missing authorization vulnerability in the Route-Level Middleware component, allowing remote attackers to perform unauthorized resource updates.</description><content:encoded><![CDATA[<p>Coolify versions up to 4.1.2 are susceptible to a security flaw identified as CVE-2026-100744, residing within the Route-Level Middleware component. Specifically, the vulnerability exists in the <code>app/Http/Middleware/CanUpdateResource.php</code> file, which fails to properly enforce authorization checks when handling requests. This flaw enables a remote, unauthenticated attacker to manipulate resource access, potentially resulting in unauthorized modifications to infrastructure or application configurations managed by Coolify. Publicly available exploit material indicates that this vulnerability is actively tracked, increasing the risk of exploitation. Defenders should prioritize updating to Coolify version 4.2.0, which includes the necessary patch (commit 39ae16de4248075de8c08f3259114e064b20d52d) to resolve the missing authorization logic.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote actors to bypass security controls and perform unauthorized operations within the Coolify dashboard. This can lead to full compromise of managed infrastructure, unauthorized deployment of malicious services, or the manipulation of application settings, posing a critical risk to environments relying on Coolify for container orchestration and self-hosted application management.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of Coolify to version 4.2.0 or later to remediate CVE-2026-100744.</li>
<li>Audit application logs for abnormal requests directed at resource-management endpoints, particularly those attempting to trigger update middleware.</li>
<li>Review access control configurations for all managed resources to ensure unintended modifications have not been performed.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>vulnerability</category><category>authentication-bypass</category></item></channel></rss>