CVE-2026-34037

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but resolves destination resources with unscoped Eloquent lookups, allowing an authenticated user to clone resources into destinations owned by other teams and access cross-tenant resources. This issue is fixed in version 4.0.0-beta.464.
Configurations

No configuration.

History

07 Jul 2026, 15:16

Type Values Removed Values Added
References () https://github.com/coollabsio/coolify/security/advisories/GHSA-ggrr-wrvr-x83v - () https://github.com/coollabsio/coolify/security/advisories/GHSA-ggrr-wrvr-x83v -

07 Jul 2026, 04:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-07 04:17

Updated : 2026-07-07 15:16


NVD link : CVE-2026-34037

Mitre link : CVE-2026-34037

CVE.ORG link : CVE-2026-34037


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key