Skip to main content
Vulnerability Database/CVE-2026-100746

CVE-2026-100746: Coolify GitHub App Authentication Bypass

CVE-2026-100746 is an authentication bypass flaw in Coolify that affects GitHub App setup handling, allowing attackers to circumvent authentication checks. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-100746 Overview

CVE-2026-100746 is a missing authentication vulnerability [CWE-287] in coollabsio Coolify versions up to 4.1.0. The flaw resides in the Github::redirect function within /webhooks/source/github/redirect, part of the GitHub App Setup Handler component. Attackers can manipulate the state argument to bypass authentication checks remotely. A public exploit exists, and the issue is resolved in version 4.1.1 via commit fc89e357feed5180ed1ab5eb9cb330578f025539.

Critical Impact

Remote, unauthenticated attackers can abuse the GitHub App redirect flow to overwrite application secrets, enabling unauthorized integration takeover of self-hosted Coolify deployments.

Affected Products

  • coollabsio Coolify versions up to and including 4.1.0
  • Coolify GitHub App Setup Handler component (Github::redirect function)
  • Self-hosted Coolify instances exposing the /webhooks/source/github/redirect endpoint

Discovery Timeline

  • 2026-09-27 - CVE-2026-100746 published to the National Vulnerability Database
  • 2026-09-28 - Last updated in NVD database

Technical Details for CVE-2026-100746

Vulnerability Analysis

The vulnerability affects the GitHub App setup redirect handler used when installing or configuring a GitHub App integration in Coolify. During normal operation, GitHub redirects the user back to Coolify with a state parameter and installation data. The Github::redirect function processes this callback and persists integration secrets without verifying that the request originated from an authenticated administrative session.

Because the state parameter is not cryptographically bound to a server-side session, a remote attacker can craft a request to /webhooks/source/github/redirect and influence which GitHub App record is updated. The public proof-of-concept, published in a CVE Discovery repository, demonstrates unauthenticated overwrite of GitHub App secrets.

Root Cause

The root cause is missing authentication on a state-changing endpoint [CWE-287]. The handler trusts the inbound state value rather than validating it against a signed, session-bound token. The upstream patch introduces Illuminate\Support\Facades\Cache and Illuminate\Support\Str to generate and verify a server-side manifestState nonce before accepting the callback.

Attack Vector

Exploitation requires only network reachability to the Coolify web interface. No credentials, user interaction, or elevated privileges are needed. An attacker who successfully overwrites GitHub App credentials can intercept subsequent webhook events, poison source control integrations, and influence deployment pipelines managed by Coolify.

php
 use App\Models\PrivateKey;
 use App\Rules\SafeExternalUrl;
 use Illuminate\Foundation\Auth\Access\AuthorizesRequests;
+use Illuminate\Support\Facades\Cache;
 use Illuminate\Support\Facades\Http;
+use Illuminate\Support\Str;
 use Lcobucci\JWT\Configuration;
 use Lcobucci\JWT\Signer\Key\InMemory;
 use Lcobucci\JWT\Signer\Rsa\Sha256;

Source: GitHub Commit fc89e357 — app/Livewire/Source/Github/Change.php. The patch adds cache-backed state validation to bind the GitHub App setup flow to a server-generated nonce.

php
                 function createGithubApp(webhook_endpoint, preview_deployment_permissions, administration) {
                     const {
                         organization,
-                        uuid,
-                        html_url
+                        html_url,
+                        uuid
                     } = @json($github_app);
                     if (!webhook_endpoint) {
                         alert('Please select a webhook endpoint.');
                         return;
                     }
                     let baseUrl = webhook_endpoint;
                     const name = @js($name);
+                    const manifestState = @js($manifestState);
                     const isDev = @js(config('app.env')) ===
                         'local';
                     const devWebhook = @js(config('constants.webhooks.dev_webhook'));

Source: GitHub Commit fc89e357 — change.blade.php. The front-end now passes a server-issued manifestState to GitHub, which the backend validates on return.

Detection Methods for CVE-2026-100746

Indicators of Compromise

  • Unauthenticated HTTP requests to /webhooks/source/github/redirect originating from unexpected source IPs
  • Unexpected modifications to GitHub App records, including changes to client_secret, webhook_secret, or private key fields
  • GitHub App installation events in Coolify that do not correlate with an administrator session in access logs

Detection Strategies

  • Review Coolify web server access logs for requests to the /webhooks/source/github/* path tree that lack a prior authenticated administrative session
  • Audit the Coolify database for recent updates to GitHub source integrations and compare against known administrator activity
  • Compare the deployed Coolify version against the fixed release by inspecting the running container image tag or git revision

Monitoring Recommendations

  • Alert on any writes to GitHub App credential fields outside of scheduled maintenance windows
  • Forward Coolify application and web logs to a central analytics platform and build detections for anonymous access to webhook setup endpoints
  • Monitor outbound traffic from Coolify to GitHub for unexpected App installation callbacks

How to Mitigate CVE-2026-100746

Immediate Actions Required

  • Upgrade Coolify to version 4.1.1 or later, which includes commit fc89e357feed5180ed1ab5eb9cb330578f025539
  • Rotate all GitHub App client secrets, webhook secrets, and private keys associated with Coolify integrations after upgrading
  • Restrict network exposure of the Coolify management interface to trusted administrator networks or a VPN

Patch Information

The fix is included in Coolify release v4.1.1 and merged via Pull Request #10362. The commit introduces a cache-backed manifestState nonce that binds the GitHub App setup redirect to a server-side session, enforcing authentication on the Github::redirect handler. See the VulDB entry for CVE-2026-100746 for additional metadata.

Workarounds

  • Place the Coolify instance behind a reverse proxy that enforces authentication or IP allowlisting on /webhooks/source/github/* paths until the upgrade is applied
  • Temporarily disable the GitHub App source integration and reconfigure it only from a trusted administrative network after patching
  • Monitor and manually review GitHub App configuration changes until the patched version is deployed
bash
# Upgrade Coolify to the patched release
cd /data/coolify
git fetch --tags
git checkout v4.1.1
./upgrade.sh

# Verify running version
docker inspect coolify --format '{{.Config.Image}}'

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.