PT-2026-99436 · Coollabsio · Coolify
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
coollabsio Coolify versions prior to 4.2.0
Description
A flaw in the Route-Level Middleware component, specifically within a function in the
app/Http/Middleware/CanUpdateResource.php file, allows for remote manipulation. This issue can lead to missing authorization, enabling an attacker to bypass security checks.Recommendations
Upgrade to version 4.2.0.
Exploit
Fix
Missing Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coolify