3.3
CVE-2026-34149
- EPSS 0.22%
- Veröffentlicht 07.07.2026 03:09:33
- Zuletzt bearbeitet 07.07.2026 15:16:44
- CVE-Watchlists
- Unerledigt
Coolify: Authenticated Host-Level RCE via Unescaped Database Credentials in Backup Jobs
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, DatabaseBackupJob interpolates user-controlled database credentials and MongoDB collection exclusion names into backup shell commands without adequate escaping, allowing an authenticated user with database management permissions to execute commands on managed servers. This issue is fixed in version 4.0.0-beta.471.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellercoollabsio
≫
Produkt
coolify
Version
< 4.0.0-beta.471
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.126 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 3.3 | 0.7 | 2.5 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471
https://github.com/coollabsio/coolify/commit/952f3247970d261ff93f85c79066192f58f9557e
https://github.com/coollabsio/coolify/commit/99043600ee881fd8581185e7590604d9882382cd
https://github.com/coollabsio/coolify/security/advisories/GHSA-4vff-6j8j-qhcg