CVE-2026-57498Disclosure

LOWCVSS 9.6 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any operation. However, multiple Livewire web UI components accept server_id and destination_uuid from URL query parameters without any team ownership validation, allowing cross-team resource deployment. This vulnerability is fixed in 4.0.0-beta.474.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-06-30: 5Patch / Workaround · 2026-06-30: 3Technical Details · 2026-06-30: 406-30
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets7 URLs
Full discourse5 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-57498 (CVSS 9.6): Livewire web UI auth bypass in Coolify before 4.0.0-beta.474 allows cross-team access to server, application, and database operations without ownership checks. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJDb29saWZ5LVNlbGYtaG9zdGluZyI= 🎯183.1K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Coolify-Self-hosting" 🔖Refer: https://github.com/coollabsio/coolify/security/advisories/GHSA-725v-f5gh-22q9 #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    CVE‑2026‑57498 is a high‑severity authentication bypass affecting Coolify versions prior to 4.0.0‑beta.474. The advisory and FOFA search details highlight the vulnerability but do not mention active exploitation or patch specifics.

    09029133.6K
    14.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-57498 Cross-Team Resource Deployment in Coolify Prior to 4.0.0-beta.474 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-57498 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet merely cites CVE-2026-57498 with a link to the vulmon database, offering no further technical details, PoC, or exploit information.

    10000147
    4.1K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical authorization bypass vulnerability #CVE-2026-57498 affects #Coolify up to v4.0.0-beta.473, allowing unauthorized access to resources. Upgrade to v4.0.0-beta.474 or later. More info: https://feedly.com/cve/CVE-2026-57498 #Patch #Patch #Patch

    Post summary

    The post highlights a critical authorization bypass (CVE-2026-57498) affecting Coolify up to v4.0.0-beta.473 and urges users to upgrade to v4.0.0-beta.474 or newer to patch the issue.

    00000400
    7.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Coolify Livewire cross-team authorization bypass (CVE-2026-57498) Coolify has an authorization flaw in multiple Livewire web UI components where server_id and destination_uuid are accepted from URL query parameters without enforcing team ownership checks. The root cause is broken access control / improper authorization (IDOR-style parameter tampering) due to missing validation of resource-to-team relationships. An attacker with low privileges can exploit this by modifying query parameters to reference servers/destinations belonging to other teams, then triggering deployments through the UI endpoints. If exploited, this enables cross-team resource deployment and unauthorized changes to infrastructure, potentially leading to service compromise, data exposure, and operational disruption. 👉 Affected: coolify < 4.0.0-beta.474 | Upgrade to 4.0.0-beta.474

    Post summary

    The message discloses a critical IDOR vulnerability in Coolify’s Livewire components, outlines exploit mechanics, and advises upgrading to version 4.0.0-beta.474 to remediate.

    0000077
    232 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-57498 - Critical Missing Authorization in #Coolify. Livewire components accept server_id without team ownership validation, enabling cross-team resource deployment. #CVSS 9.6. No patch available. Restrict access immediately. #devsecops #devops #infosec More: https://www.valtersit.com/cve/CVE-2026-57498

    Post summary

    The post discloses a critical missing‑authorization flaw in Coolify (CVE‑2026‑57498) that allows cross‑team resource deployment, scoring CVSS 9.6. No patch exists yet, so immediate access restriction is advised.

    0000090
    967 followersView on X

Explore more