Insecure API Endpoint in Coolify Affects Server Management
CVE-2026-27956
4.3MEDIUM
What is CVE-2026-27956?
Coolify, an open-source self-hostable server management tool, has a vulnerability in the API endpoint that allows authenticated users to bypass team permissions. Specifically, when the optional UUID query parameter is utilized, any authenticated user can list fully qualified domain names (FQDNs) of applications associated with other teams, potentially compromising sensitive information. To mitigate this issue, users are advised to upgrade to version 4.0.0-beta.464 or later.
Affected Version(s)
coolify < 4.0.0-beta.464
