AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-34035

HIGH · CVSS 8.8 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

Coolify versions prior to 4.0.0-beta.466 are vulnerable to command injection due to insufficient encoding of log drain secrets and environment values within shell commands. This flaw allows authenticated users to execute arbitrary commands on the host, posing a significant security risk. Organizations using Coolify should prioritize upgrading to the fixed version to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-34035
Severity
HIGH
CVSS
8.8
EPSS
0.34%

Original NVD Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, log drain secret and environment values were interpolated into shell commands without sufficient encoding, allowing an authenticated user to inject commands executed on the host. This issue is fixed in version 4.0.0-beta.466.