9.9
CVE-2026-34037
- EPSS 0.3%
- Veröffentlicht 07.07.2026 03:21:52
- Zuletzt bearbeitet 07.07.2026 15:16:43
- CVE-Watchlists
- Unerledigt
Cross-Tenant Resource Cloning via Broken Object-Level Authorization in cloneTo()
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but resolves destination resources with unscoped Eloquent lookups, allowing an authenticated user to clone resources into destinations owned by other teams and access cross-tenant resources. This issue is fixed in version 4.0.0-beta.464.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellercoollabsio
≫
Produkt
coolify
Version
< 4.0.0-beta.464
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.219 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 9.9 | 3.1 | 6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://github.com/coollabsio/coolify/commit/1759a1631cd63271ebf6caa250c6d93440eaa333
https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.464
https://github.com/coollabsio/coolify/security/advisories/GHSA-ggrr-wrvr-x83v