PatchSiren cyber security CVE debrief
CVE-2026-42172 coollabsio CVE debrief
Coolify, an open-source tool for managing servers, applications, and databases, had an issue with Sanctum API tokens not expiring. This allowed leaked tokens to retain access indefinitely until manually revoked. The issue was fixed in version 4.0.0-beta.474. Affected users should verify their installations and update to the latest version to ensure token expiration. The vulnerability has a low CVSS score of 3.1 and is considered a low priority for users of Coolify versions prior to 4.0.0-beta.474.
- Vendor
- coollabsio
- Product
- coolify
- CVSS
- LOW 3.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-07
- Original CVE updated
- 2026-07-07
- Advisory published
- 2026-07-07
- Advisory updated
- 2026-07-07
Who should care
Users of Coolify versions prior to 4.0.0-beta.474 should verify their installations and update to the latest version to ensure token expiration. This includes operators, platform administrators, vulnerability management teams, and security teams who manage Coolify deployments.
Technical summary
Coolify, an open-source tool for managing servers, applications, and databases, had an issue with Sanctum API tokens not expiring. This allowed leaked tokens to retain access indefinitely until manually revoked. The issue was fixed in version 4.0.0-beta.474. Users of Coolify versions prior to 4.0.0-beta.474 should verify their installations and update to the latest version to ensure token expiration. The vulnerability has a low CVSS score of 3.1 and is considered a low priority.
Defensive priority
Medium priority for users of Coolify versions prior to 4.0.0-beta.474
Recommended defensive actions
- Update to Coolify version 4.0.0-beta.474 or later
- Verify and revoke any existing Sanctum API tokens
- Monitor for suspicious activity related to API tokens
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further investigation is needed to determine the full scope of the issue. Evidence is limited, and defenders should verify Coolify installations, review Sanctum API token usage, and monitor for suspicious activity. The vulnerability affects Coolify versions prior to 4.0.0-beta.474, and users should update to the latest version to ensure token expiration.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42172 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42172
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42172 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42172
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/coollabsio/coolify/commit/b1a78df58efe3ac38679d18c888b5817c7f01216
-
Source reference
Unverified legacy reference
URL: https://github.com/coollabsio/coolify/pull/9677
-
Source reference
Unverified legacy reference
URL: https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474
-
Source reference
Unverified legacy reference
URL: https://github.com/coollabsio/coolify/security/advisories/GHSA-c83f-5ph7-x8xv
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.