Coolify Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability exists in Coolify versions through v4.0.0-beta.434. A low privileged user can access and use invitation links intended for administrators. By using the link before the administrator, the user can log in as an admin, thereby escalating their privileges.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling a low privileged user to gain administrative rights.

Reproduction

To reproduce this vulnerability, a low privileged user must access invitation links sent to administrators. Once the user has the link, they can use it to log in as an administrator, effectively escalating their privileges.

Added: Jan 5, 2026, 9:20 PM
Updated: Jan 5, 2026, 10:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.2
remediation
0.0
relevance
1.9
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.