Skip to main content
Vulnerability Database/CVE-2026-100744

CVE-2026-100744: Coolify Authorization Bypass Vulnerability

CVE-2026-100744 is an authorization bypass flaw in Coolify that allows attackers to circumvent authentication controls remotely. This post covers the technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-100744 Overview

CVE-2026-100744 is a missing authorization vulnerability [CWE-862] in coollabsio Coolify versions up to 4.1.2. The flaw resides in the app/Http/Middleware/CanUpdateResource.php file within the Route-Level Middleware component. An attacker can exploit the flaw remotely over the network without authentication or user interaction. Successful exploitation enables unauthorized modification of team resources that should be restricted to admins or owners. The vendor has published a fix in commit 39ae16de4248075de8c08f3259114e064b20d52d, and users should upgrade to version 4.2.0 to remediate the issue. A public exploit has been disclosed.

Critical Impact

Remote attackers can bypass route-level authorization checks in Coolify to perform resource updates reserved for privileged team roles.

Affected Products

  • coollabsio Coolify versions up to and including 4.1.2
  • app/Http/Middleware/CanUpdateResource.php (Route-Level Middleware)
  • app/Policies/TeamPolicy.php team authorization policy

Discovery Timeline

  • 2026-09-27 - CVE-2026-100744 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-100744

Vulnerability Analysis

The vulnerability stems from an incomplete authorization check in Coolify's route-level middleware. The CanUpdateResource middleware governs whether a user can modify team-scoped resources such as Application, Environment, Project, Service, ServiceApplication, and ServiceDatabase. Because the middleware did not fully resolve all resource types, including Server, requests reaching protected update routes could pass through without a proper authorization decision. This permitted team members without admin or owner privileges to invoke update actions on resources outside their intended scope.

The companion fix in app/Policies/TeamPolicy.php replaces a global isAdmin() || isOwner() check with the team-scoped isAdminOfTeam($team->id) check. The prior logic treated any admin or owner role as sufficient to update or delete any team the user belonged to, regardless of role within that specific team.

Root Cause

The root cause is missing authorization logic [CWE-862]. The middleware and policy evaluated coarse-grained role flags rather than enforcing per-team role verification and complete resource-type coverage.

Attack Vector

An unauthenticated or low-privileged remote attacker sends crafted HTTP requests to Coolify endpoints protected by the CanUpdateResource middleware. Because exploit code is publicly available, scripted exploitation against exposed Coolify instances is feasible.

php
// Patch: app/Http/Middleware/CanUpdateResource.php
 use App\Models\Application;
 use App\Models\Environment;
 use App\Models\Project;
+use App\Models\Server;
 use App\Models\Service;
 use App\Models\ServiceApplication;
 use App\Models\ServiceDatabase;

Source: GitHub Commit 39ae16d

php
// Patch: app/Policies/TeamPolicy.php
 public function update(User $user, Team $team): bool
 {
-    // Only admins and owners can update team settings
     if (! $user->teams->contains('id', $team->id)) {
         return false;
     }

-    return $user->isAdmin() || $user->isOwner();
+    return $user->isAdminOfTeam($team->id);
 }

 public function delete(User $user, Team $team): bool
 {
-    // Only admins and owners can delete teams
     if (! $user->teams->contains('id', $team->id)) {
         return false;
     }

-    return $user->isAdmin() || $user->isOwner();
+    return $user->isAdminOfTeam($team->id);
 }

Source: GitHub Commit 39ae16d

Detection Methods for CVE-2026-100744

Indicators of Compromise

  • Unexpected PUT, PATCH, or POST update requests to Coolify team resource endpoints from non-admin accounts.
  • Audit log entries showing resource modifications performed by users without isAdminOfTeam membership.
  • Repeated 2xx responses on update routes previously returning 403 for the same user.

Detection Strategies

  • Compare authenticated session role claims against the acting user's team role before accepting update actions.
  • Alert when a single account enumerates multiple team resource identifiers within a short interval.
  • Monitor for access to Server, Application, Service, and related endpoints originating from accounts lacking admin rights.

Monitoring Recommendations

  • Enable verbose web server and Laravel application logging for routes guarded by CanUpdateResource middleware.
  • Forward Coolify application logs to a centralized SIEM for cross-user correlation.
  • Track installed Coolify versions across your fleet and flag any instance still running 4.1.2 or earlier.

How to Mitigate CVE-2026-100744

Immediate Actions Required

  • Upgrade Coolify to version 4.2.0 or later, which includes patch commit 39ae16de4248075de8c08f3259114e064b20d52d.
  • Audit team membership and role assignments to identify unexpected admin or owner grants.
  • Restrict external network exposure of Coolify management interfaces until the patch is applied.

Patch Information

The vendor fix is included in Coolify v4.2.0 via Pull Request #10829. Additional context is available at VulDB CVE-2026-100744.

Workarounds

  • Place Coolify behind an authenticated reverse proxy or VPN to limit anonymous network reachability.
  • Enforce IP allowlisting on management routes while planning the upgrade.
  • Temporarily reduce the number of users with team membership to minimize the exploitable surface.
bash
# Upgrade Coolify to the patched release
curl -fsSL https://cdn.coollabs.io/coolify/install.sh | bash
# Verify the installed version
docker inspect coolify --format '{{.Config.Image}}'

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.