AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-34171

HIGH · CVSS 8 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

The vulnerability allows an attacker to exploit the GET /invitations/{uuid} endpoint in Coolify versions prior to 4.0.0-beta.471 to reset a victim's account password using a known invitation UUID. This can lead to unauthorized access to user accounts, posing a significant risk to user data and application integrity. Organizations using affected versions should prioritize upgrading to the fixed version to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-34171
Severity
HIGH
CVSS
8
EPSS
0.15%

Original NVD Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GET /invitations/{uuid} endpoint can perform a state-changing password reset using an attacker-known invitation UUID, allowing an attacker who can cause a victim to visit the crafted invitation URL to reset the victim account password to a predictable value. This issue is fixed in version 4.0.0-beta.471.