PatchSiren cyber security CVE debrief
CVE-2026-34171 coollabsio CVE debrief
CVE-2026-34171 is a high-severity vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The vulnerability exists in the GET /invitations/{uuid} endpoint, which can perform a state-changing password reset using an attacker-known invitation UUID. This allows an attacker who can cause a victim to visit the crafted invitation URL to reset the victim account password to a predictable value. The issue is fixed in version 4.0.0-beta.471. Users of Coolify should review their current version and update to 4.0.0-beta.471 or later to prevent potential password reset attacks. This vulnerability has a high CVSS score of 8 and is considered a high-priority issue. The NVD entry for this vulnerability is currently Deferred.
- Vendor
- coollabsio
- Product
- coolify
- CVSS
- HIGH 8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-07
- Original CVE updated
- 2026-07-07
- Advisory published
- 2026-07-07
- Advisory updated
- 2026-07-07
Who should care
Users of Coolify versions prior to 4.0.0-beta.471 should update to the latest version to prevent potential password reset attacks. This includes administrators, developers, and security teams responsible for managing and securing Coolify deployments. Additionally, security teams should review and update any existing invitations to ensure they are not vulnerable.
Technical summary
CVE-2026-34171 is a high-severity vulnerability in Coolify, an open-source tool for managing servers, applications, and databases. The vulnerability exists in the GET /invitations/{uuid} endpoint, which can perform a state-changing password reset using an attacker-known invitation UUID. This allows an attacker who can cause a victim to visit the crafted invitation URL to reset the victim account password to a predictable value. The issue is fixed in version 4.0.0-beta.471.
Defensive priority
High priority should be given to updating Coolify to version 4.0.0-beta.471 or later to prevent potential password reset attacks.
Recommended defensive actions
- Update Coolify to version 4.0.0-beta.471 or later
- Review and update any existing invitations to ensure they are not vulnerable
- Monitor for any suspicious activity related to password resets
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability is confirmed to exist in Coolify versions prior to 4.0.0-beta.471. The fix is included in version 4.0.0-beta.471. Users should update to the latest version to prevent potential password reset attacks. The CVE record was published on 2026-07-07T04:17:50.513Z and has not been modified since then. The NVD entry is currently Deferred.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-34171 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-34171
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-34171 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34171
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/coollabsio/coolify/commit/25d424c743d5134d4a005a6d8f754bb3235b632c
-
Source reference
Unverified legacy reference
URL: https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.471
-
Source reference
Unverified legacy reference
URL: https://github.com/coollabsio/coolify/security/advisories/GHSA-389w-cc6x-wr2m
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.