Missing Authentication Vulnerability in Coolify by Coollabsio
CVE-2026-100746
Key Information:
- Vendor
Coollabsio
- Status
- Vendor
- CVE Published:
- 27 September 2026
Badges
What is CVE-2026-100746?
A flaw has been identified in the GitHub App Setup Handler of Coolify versions up to 4.1.0, where the function Github::redirect fails to enforce proper authentication for the 'state' argument. This weakness enables unauthorized parties to exploit the system remotely, potentially leading to security breaches. Users are advised to upgrade to version 4.1.1, which includes necessary patches to address this issue. The specific patch is identified as fc89e357feed5180ed1ab5eb9cb330578f025539.
Affected Version(s)
Coolify 4.0
Coolify 4.1.0
Coolify 4.1.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
