Coolify · Coolify · CVE-2026-34034
**Name of the Vulnerable Software and Affected Versions**
Coolify versions prior to 4.0.0-beta.466
**Description**
An authenticated user with access to server Sentinel settings can execute commands on the host when Sentinel is restarted. This occurs because the `sentinel token` setting is used in shell commands without sufficient validation, allowing for the injection of shell syntax.
**Recommendations**
Update to version 4.0.0-beta.466.