CVE-2026-34594: Coolify Command Injection in Destination Network Management
Coolify, a popular open-source platform for managing servers, applications, and databases, contains a command injection flaw in its Destination Network Management feature. An authenticated user with permission to manage destinations can inject arbitrary shell commands into network configuration parameters, resulting in uncontrolled code execution as root on any managed server. The vulnerability exists in all versions prior to 4.0.0-beta.471 and has been patched in that release.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.8 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-78
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-29 / 2026-07-01
NVD description (verbatim)
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, an authenticated command injection vulnerability in the Destination Network Management functionality allows users with destination management permissions to execute arbitrary commands as root on managed servers. The "network" parameter is passed directly to shell commands without proper sanitization, enabling full remote code execution on the host system. This vulnerability is fixed in 4.0.0-beta.471.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-34594 is an authenticated command injection vulnerability (CWE-78) in Coolify's Destination Network Management functionality. The 'network' parameter is concatenated directly into shell command strings without input validation or escaping, allowing privilege-escalated command execution. An attacker with destination management permissions can craft malicious input to break out of the intended command context and execute arbitrary commands with root privileges on the underlying host. The vulnerability requires prior authentication but no additional user interaction.
Business impact
This vulnerability poses a severe risk to organizations using Coolify for infrastructure management. Compromise of a Coolify instance grants an attacker root-level access to all managed servers simultaneously, enabling data theft, service disruption, malware installation, and lateral movement within the managed infrastructure. For teams relying on Coolify for multi-server orchestration, a single compromised user account with destination management rights can compromise an entire managed fleet. Incident response and forensic costs, combined with potential downtime and data loss, make this a business-critical remediation priority.
Affected systems
All versions of Coolify prior to 4.0.0-beta.471 are vulnerable. The flaw affects any Coolify deployment where users have been granted destination management permissions. Organizations running self-hosted Coolify instances should inventory their current version immediately and identify which users hold destination management roles, as those accounts represent the primary attack surface.
Exploitability
The vulnerability requires an authenticated account with destination management permissions but is otherwise trivial to exploit—no complex exploitation techniques or race conditions are needed. The attack is network-accessible and requires no user interaction beyond the attacker's own actions. Given that many organizations grant destination management permissions to operational teams for legitimate infrastructure management tasks, the pool of potential exploiters may be larger than for purely administrative flaws. No public exploit code or active exploitation has been confirmed at this time, but the straightforward nature of command injection makes weaponization straightforward.
Remediation
Organizations must upgrade Coolify to version 4.0.0-beta.471 or later. Before patching, apply compensating controls: restrict destination management permissions to only essential personnel, implement network segmentation to limit lateral movement from compromised Coolify instances, and monitor Coolify logs and managed server activity for anomalous command execution. Post-patch, validate that the upgrade completed successfully and review audit logs for evidence of prior exploitation.
Patch guidance
Upgrade Coolify to 4.0.0-beta.471 or any subsequent stable release. Follow the official Coolify upgrade documentation for your deployment model (Docker, standalone, etc.). Test the upgrade in a non-production environment first to ensure compatibility with your current configuration and any custom integrations. After deployment, restart the Coolify service and verify connectivity to all managed destinations. Document the patch date and version for compliance and incident tracking purposes.
Detection guidance
Monitor Coolify application logs for unusual shell command patterns in destination network management operations—look for special characters, command separators (semicolons, pipes, backticks), or suspicious arguments. Correlate Coolify audit logs with managed server activity to identify unexpected command execution, particularly outbound connections, package installations, or user account creation on managed hosts. Network-based detection should flag DNS exfiltration attempts or unexpected outbound connections originating from managed servers shortly after Coolify API calls. Behavioral baselining of legitimate destination management workflows will help distinguish malicious from benign network parameter changes.
Why prioritize this
Despite CVE-2026-34594 not appearing on the CISA Known Exploited Vulnerabilities list as of publication, the combination of high CVSS score (8.8), root-level code execution, network accessibility, and authentication-only requirements makes this a critical patch priority. Command injection vulnerabilities in infrastructure management tools are particularly dangerous because they compromise the trust relationship between operator and managed systems. Organizations should treat this as an emergency patch candidate, second only to zero-days and active exploitation scenarios.
Risk score, explained
The CVSS 3.1 score of 8.8 reflects high attack complexity (network-accessible, no user interaction required) balanced against the requirement for prior authentication and limited scope. The score correctly elevates impact (confidentiality, integrity, and availability all high) but does not account for the organizational risk multiplier—that an attacker controlling Coolify can simultaneously compromise dozens or hundreds of managed servers. Real-world risk is context-dependent: organizations with strong access controls on Coolify accounts and network isolation may operate closer to CVSS baseline, while those with permissive account provisioning or Coolify instances exposed to untrusted networks face significantly higher risk.
Frequently asked questions
We use Coolify internally for a small team. How urgent is patching?
Very urgent. Even if your team is trusted, a compromised credential or insider threat would grant root access to all managed infrastructure. Patch immediately, and review who holds destination management permissions—principle of least privilege should limit this role to a minimal set of operators.
Can we safely run older Coolify versions behind a firewall or VPN?
Network isolation reduces but does not eliminate risk, especially for insider threats or if the network perimeter is breached. Authentication is still required, so unpatched versions remain vulnerable to any user with destination management rights. Patching is the only reliable mitigation.
How can we tell if we've been exploited?
Review Coolify audit logs for destination management changes and unexpected shell commands. Check managed server logs and process execution histories for anomalous activity coinciding with Coolify usage. Look for unauthorized user accounts, cron jobs, or persistence mechanisms on managed servers. Engage a forensic team if evidence of compromise is found.
Does this affect managed Coolify services (cloud-hosted versions)?
This CVE applies to self-hosted Coolify deployments. If your Coolify instance is managed by a vendor or cloud provider, contact them to confirm their patch status and timeline. Do not assume cloud hosting removes this risk; verify directly with your provider.
This analysis is provided for informational purposes and does not constitute legal, compliance, or professional security advice. Organizations must independently verify patch availability, compatibility, and applicability to their environment. CVSS scores and severity ratings are provided as reference; risk assessment must account for specific organizational context, asset criticality, and threat landscape. No liability is assumed for decisions made based on this intelligence. Always consult official vendor advisories and test patches in controlled environments before production deployment. Source: NVD (public-domain), retrieved 2026-08-08. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2025-41265HIGHWaterfall WF-500 TX Host OS Command Injection (CVSS 7.2)
- CVE-2025-41266HIGHWaterfall WF-500 TX Host Command Injection Vulnerability Analysis
- CVE-2025-41267HIGHWaterfall WF-500 TX Host Command Injection Vulnerability
- CVE-2025-41279HIGHOS Command Injection in Waterfall WF-500 RX Host Administration WebUI
- CVE-2025-41281HIGHWaterfall WF-500 OS Command Injection
- CVE-2025-66273HIGHQNAP Command Injection in QTS and QuTS hero
- CVE-2025-66279HIGHQNAP NAS Command Injection – Admin Authentication Required, HIGH Severity
- CVE-2025-69755HIGHNeterbit NW-431F Router RCE and Data Exposure Vulnerability