Coolify · Coolify · CVE-2026-34050
**Name of the Vulnerable Software and Affected Versions**
Coolify versions prior to 4.0.0-beta.471
**Description**
The Settings/Updates Livewire component fails to verify the `isInstanceAdmin` status within its `mount()` function. This allows users without administrative privileges to access the Updates settings page, where they may trigger update checks or modify auto-update configurations.
**Recommendations**
Update to version 4.0.0-beta.471.