Authentication Bypass Vulnerability in Coolify by Coollabs.io
CVE-2026-86117

9.2CRITICAL

Key Information:

Vendor

Coollabsio

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86117?

Coolify versions up to 4.3.17 are vulnerable due to an authentication bypass flaw present in the OAuth callback handler. This vulnerability allows attackers to gain unauthorized access to users' accounts solely by exploiting email addresses. The flaw enables attackers to register a victim's email address with any enabled OAuth provider, subsequently signing in as that user without the need for a password or two-factor authentication. As a result, the integrity and confidentiality of user accounts could be significantly compromised, providing malicious actors with unauthorized access to private information and functionalities.

Affected Version(s)

coolify 0 <= 4.3.17

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.