CVE-2026-100744

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component Route-Level Middleware. Executing a manipulation can lead to missing authorization. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 4.2.0 is sufficient to fix this issue. This patch is called 39ae16de4248075de8c08f3259114e064b20d52d. It is advisable to upgrade the affected component.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-27: 109-27
Referenced assets1 URL
By indicator
Full discourse1 post
  • VulnTracker@vuln_tracker

    Two Coolify vulnerabilities disclosed the same day, and both already have public exploits (CVSS 7.3 each). CVE-2026-100744: missing authorization in the route-level middleware lets a remote attacker manipulate resources without permission. Fixed in 4.2.0. CVE-2026-100746: the GitHub App Setup redirect handler skips authentication entirely, letting a remote attacker overwrite GitHub app secrets. Fixed in 4.1.1. Update now, exploit code for both is already out there. Details: http://vulntracker.io/cves/CVE-2026-100744 #Coolify #CVE #InfoSec #CyberSecurity

    0100182
    773 followersView on X

Explore more