CVE-2026-100744 Details
Description
A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component Route-Level Middleware. Executing a manipulation can lead to missing authorization. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 4.2.0 is sufficient to fix this issue. This patch is called 39ae16de4248075de8c08f3259114e064b20d52d. It is advisable to upgrade the affected component.
A vulnerability allowing missing authorization has been identified in Coollabsio Coolify versions through 4.1.2. The issue resides in the route-level middleware, specifically within the file 'app/Http/Middleware/CanUpdateResource.php'. This flaw can be exploited remotely by manipulating certain route parameters, leading to unauthorized actions on resources.
Users are advised to upgrade to Coolify version 4.2.0, where this vulnerability has been fixed. The update can be obtained from the Coolify GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/coollabsio/coolify/ | [email protected] | Vendor |
| https://github.com/coollabsio/coolify/commit/39ae16de4248075de8c08f3259114e064b20d52d | [email protected] | Source CodeVendor |
| https://github.com/coollabsio/coolify/pull/10829 | [email protected] | Issue TrackingVendor |
| https://github.com/coollabsio/coolify/releases/tag/v4.2.0 | [email protected] | Release NotesVendor |
| https://github.com/lakshayyverma/CVE-Discovery/blob/main/coolify-missing-authorization-route-middleware.7z | [email protected] | |
| https://vuldb.com/cve/CVE-2026-100744 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/897358 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/410615 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/410615/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| coollabsio Coolify | <= 4.1.2 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion