Authentication Bypass Vulnerability in Coolify by Coollabs.io
CVE-2026-86117
9.2CRITICAL
What is CVE-2026-86117?
Coolify versions up to 4.3.17 are vulnerable due to an authentication bypass flaw present in the OAuth callback handler. This vulnerability allows attackers to gain unauthorized access to users' accounts solely by exploiting email addresses. The flaw enables attackers to register a victim's email address with any enabled OAuth provider, subsequently signing in as that user without the need for a password or two-factor authentication. As a result, the integrity and confidentiality of user accounts could be significantly compromised, providing malicious actors with unauthorized access to private information and functionalities.
Affected Version(s)
coolify 0 <= 4.3.17
