CVE-2026-100746

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup Handler. The manipulation of the argument state results in missing authentication. The attack can be executed remotely. The exploit has been made public and could be used. Upgrading to version 4.1.1 mitigates this issue. The patch is identified as fc89e357feed5180ed1ab5eb9cb330578f025539. The affected component should be upgraded.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-27: 109-27
Referenced assets1 URL
By indicator
Full discourse1 post
  • VulnTracker@vuln_tracker

    Two Coolify vulnerabilities disclosed the same day, and both already have public exploits (CVSS 7.3 each). CVE-2026-100744: missing authorization in the route-level middleware lets a remote attacker manipulate resources without permission. Fixed in 4.2.0. CVE-2026-100746: the GitHub App Setup redirect handler skips authentication entirely, letting a remote attacker overwrite GitHub app secrets. Fixed in 4.1.1. Update now, exploit code for both is already out there. Details: http://vulntracker.io/cves/CVE-2026-100744 #Coolify #CVE #InfoSec #CyberSecurity

    0100182
    773 followersView on X

Explore more