
⚠️⚠️ CVE-2026-57498 (CVSS 9.6): Livewire web UI auth bypass in Coolify before 4.0.0-beta.474 allows cross-team access to server, application, and database operations without ownership checks. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJDb29saWZ5LVNlbGYtaG9zdGluZyI= 🎯183.1K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Coolify-Self-hosting" 🔖Refer: https://github.com/coollabsio/coolify/security/advisories/GHSA-725v-f5gh-22q9 #OSINT #FOFA #CyberSecurity #Vulnerability
Post summary
CVE‑2026‑57498 is a high‑severity authentication bypass affecting Coolify versions prior to 4.0.0‑beta.474. The advisory and FOFA search details highlight the vulnerability but do not mention active exploitation or patch specifics.




