PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-64423 Coollabs CVE debrief

A low-privileged user in Coolify versions up to and including v4.0.0-beta.434 can escalate privileges to an administrator by using invitation links intended for administrators. This issue arises because low-privileged users can access and use invitation links meant for administrators before the intended recipient does, allowing them to log in as an administrator.

Vendor
Coollabs
Product
Coolify
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-05
Original CVE updated
2026-09-30
Advisory published
2026-01-05
Advisory updated
2026-09-30

Who should care

Defenders managing Coolify deployments, especially those with low-privileged users who have access to administrator-targeted invitation links, should assess their exposure and prioritize verification of current version numbers and compensating controls.

Why it matters

CVE-2025-64423 is a high-severity vulnerability in Coolify that allows low-privileged users to escalate privileges to an administrator. Defenders should verify exposure, prioritize patching or mitigation, and monitor for unusual activity.

  • Privilege escalation from low-privileged user to administrator
  • Potential unauthorized access to sensitive information
  • Possible disruption of service due to misuse of administrator privileges
  • Need for verification of current Coolify version and exposure

Technical summary

In Coolify versions up to and including v4.0.0-beta.434, a low-privileged user can escalate privileges to an administrator. This is possible because low-privileged users can access and use invitation links intended for administrators before the legitimate recipient does. The vulnerability allows for privilege escalation from a low-privileged user to an administrator, potentially leading to unauthorized access to sensitive information and disruption of service due to misuse of administrator privileges. Defenders should prioritize verifying exposure in their Coolify deployments, especially where low-privileged users have access to administrator-targeted invitation links.

Defensive priority

Defenders should prioritize verifying exposure in their Coolify deployments, especially where low-privileged users have access to administrator-targeted invitation links. They should also verify current version numbers and assess the effectiveness of existing compensating controls.

Recommended defensive actions

  • Verify current Coolify version and compare to v4.0.0-beta.434
  • Restrict access to administrator-targeted invitation links
  • Monitor for unusual login activity
  • Implement additional logging and monitoring for low-privileged user activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE Program record and NVD vulnerability detail provide official information on the vulnerability. A source reference from GitHub offers additional context on the issue. Defenders should verify exposure in their Coolify deployments, especially where low-privileged users have access to administrator-targeted invitation links. They should also verify current version numbers and assess the effectiveness of existing compensating controls. The vulnerability allows low-privileged users to escalate privileges to an administrator by using

Sources and references

Verified primary and authoritative sources

  • CVE-2025-64423 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-64423

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-64423 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64423

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/coollabsio/coolify/security/advisories/GHSA-4fqm-797g-7m6j

    [email protected] - Exploit, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.