CVE-2026-27957 Details
Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, an authenticated command injection vulnerability in the CA Certificate management feature allows any authenticated user to execute arbitrary commands as the configured SSH user on the managed server host. As the SSH user typically would have to either be root or part of the docker group for Coolify to function as intended, this provides complete compromise of the managed server and associated docker containers. This vulnerability is fixed in 4.0.0-beta.464.
A command injection vulnerability allowing authenticated users to execute arbitrary commands on the managed server host has been identified in Coolify versions prior to 4.0.0-beta.464. This vulnerability arises in the CA Certificate management feature, where user-supplied certificates are not properly validated before being written to the server. As a result, an attacker can inject commands that are executed as the configured SSH user, which typically has root privileges or Docker access. Exploitation of this vulnerability could lead to a complete compromise of the managed server and its Docker containers.
Users are advised to update to Coolify version 4.0.0-beta.464 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/coollabsio/coolify/security/advisories/GHSA-7g97-c4xv-3cjx | CISA-ADP | AdvisoryExploitRemedyTechnical AnalysisVendor |
| https://github.com/coollabsio/coolify/security/advisories/GHSA-7g97-c4xv-3cjx | [email protected] | AdvisoryExploitRemedyTechnical AnalysisVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Coolify | <= 4.0.0-beta.463 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion