Insecure API Endpoint in Coolify Affects Server Management
CVE-2026-27956

4.3MEDIUM

Key Information:

Vendor

Coollabsio

Status
Vendor
CVE Published:
30 June 2026

What is CVE-2026-27956?

Coolify, an open-source self-hostable server management tool, has a vulnerability in the API endpoint that allows authenticated users to bypass team permissions. Specifically, when the optional UUID query parameter is utilized, any authenticated user can list fully qualified domain names (FQDNs) of applications associated with other teams, potentially compromising sensitive information. To mitigate this issue, users are advised to upgrade to version 4.0.0-beta.464 or later.

Affected Version(s)

coolify < 4.0.0-beta.464

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.