AUGUST 21, 2026
Live Feed
Back to database
Case File

CVE-2026-32718

MEDIUM · CVSS 6.5 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

Coolify versions prior to 4.0.0-beta.466 are vulnerable due to inadequate protection on mutating API validation endpoints, allowing read-scoped API tokens to execute state-changing operations like validating cloud tokens and servers. This could lead to unauthorized modifications and potential compromise of server management. Organizations using affected versions should prioritize upgrading to the fixed version to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-32718
Severity
MEDIUM
CVSS
6.5
EPSS
0.21%

Original NVD Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, mutating API validation endpoints are guarded by read ability, allowing read-scoped API tokens to perform state-changing operations such as validating cloud tokens and servers. This issue is fixed in version 4.0.0-beta.466.