CVE-2026-100746
published 2026-09-27CVE-2026-100746: A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the…
PriorityP350high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.50%
40.6th percentile
A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup Handler. The manipulation of the argument state results in missing authentication. The attack can be executed remotely. The exploit has been made public and could be used. Upgrading to version 4.1.1 mitigates this issue. The patch is identified as fc89e357feed5180ed1ab5eb9cb330578f025539. The affected component should be upgraded.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coollabsio | coolify | — | — |
| coollabsio | coolify | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/coollabsio/coolify/https://github.com/coollabsio/coolify/commit/fc89e357feed5180ed1ab5eb9cb330578f025539https://github.com/coollabsio/coolify/pull/10362https://github.com/coollabsio/coolify/releases/tag/v4.1.1https://github.com/lakshayyverma/CVE-Discovery/blob/main/coolify-unauth-secret-overwrite-github-app-redirect.7zhttps://vuldb.com/cve/CVE-2026-100746https://vuldb.com/submit/897404https://vuldb.com/vuln/410617https://vuldb.com/vuln/410617/cti
2026-09-27
Published