CVE-2026-34048 is an improper authorization vulnerability in Coolify, an open-source self-hosted platform for managing servers, applications, and databases. In versions prior to 4.0.0-beta.471, the terminal websocket bootstrap routes verify that a user is authenticated but fail to enforce the terminal authorization restrictions applied by the user interface. As a result, a low-privileged team member can connect directly to terminal routes intended for administrators and obtain interactive command execution on team-managed servers. The flaw affects the authorization logic protecting terminal session establishment rather than the terminal feature itself, creating a privilege-boundary bypass within a team context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical authorization flaw in Coolify's terminal websocket bootstrap routes that allows low-privileged members to access admin-only terminal sessions and achieve remote command execution, with researchers reproducing root access in a lab.
An improper authorization vulnerability in Coolify terminal websocket bootstrap routes that allows a low-privileged authenticated team member to access terminal routes and execute commands on team servers.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.