SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-34038

CRITICAL · CVSS 9.9 EPSS 1.75% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

An authenticated remote command injection vulnerability in Coolify prior to version 4.0.0-beta.469 allows users with application write permissions to execute arbitrary code remotely and exfiltrate sensitive environment variables through deployment logs. This critical flaw poses a significant risk to any organization using Docker for application deployment, particularly those with less stringent access controls. Organizations leveraging Coolify should prioritize upgrading to the fixed version to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-34038
Severity
CRITICAL
CVSS
9.9
EPSS
1.75%
Docker

Original NVD Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows users with application write permissions to achieve remote code execution and exfiltrate sensitive environment variables through deployment logs via fields such as dockerfile_location and deployment commands. This issue is fixed in version 4.0.0-beta.469.