PT-2026-56140 · Coolify · Coolify

·

CVE-2026-42172

·

Published

2026-07-07

·

Updated

2026-07-07

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Coolify versions prior to 4.0.0-beta.474
Description Sanctum API tokens do not expire, which allows a leaked token to maintain access indefinitely unless it is manually revoked.
Recommendations Update to version 4.0.0-beta.474.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42172
GHSA-C83F-5PH7-X8XV

Affected Products

Coolify