SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-34049

LOW · CVSS 3.3 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

The vulnerability affects Coolify versions 4.0.0-beta.451 through 4.0.0-beta.470, specifically in the handling of MongoDB collection names during database backup processes, where insufficient validation of shell metacharacters allows for command injection by a highly privileged attacker. Although classified as low severity, organizations using affected versions should prioritize upgrading to version 4.0.0-beta.471 to mitigate potential risks associated with unauthorized command execution. Users with the ability to configure backup inputs should be particularly vigilant.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-34049
Severity
LOW
CVSS
3.3
EPSS
0.19%
MongoDB

Original NVD Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.451 through 4.0.0-beta.470, database backup handling for MongoDB collection names did not fully validate shell metacharacters, allowing a highly privileged attacker who can configure backup inputs to inject commands. This issue is fixed in version 4.0.0-beta.471.