logo

Self-Hosters Beware: 3 Critical Coolify Flaws Grant Root Access

ID: 3066bd98-9b4f-5d0f-93ab-9376b367a594

STIX ID: report--3066bd98-9b4f-5d0f-93ab-9376b367a594

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

Author: Ddos

...
...

Security researchers disclosed three critical Coolify vulnerabilities—two command-injection flaws and one private SSH key disclosure—that allow low-privileged users or malicious repositories to execute arbitrary commands as root or obtain SSH keys, with roughly 52,000 exposed instances worldwide; administrators are urged to upgrade to patched versions immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.