CVE-2026-86117
published 2026-09-05CVE-2026-86117: Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on…
PriorityP355high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.42%
36.2th percentile
Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers can register a victim's email address on any enabled OAuth provider to obtain authenticated sessions as that user, bypassing password requirements and two-factor authentication.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coollabsio | coolify | <= 4.3.17 | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider as
ghsa_unreviewed·2026-09-05
CVE-2026-86117 [CRITICAL] CWE-287 Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider as
Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers can register a victim's email address on any enabled OAuth provider to obtain authenticated sessions as that user, bypassing password requirements and two-factor authentication.
VulDB
CoolLabs Coolify up to 4.3.17 OAuth Callback assertion (EUVD-2026-71949)
vuldb·2026-09-05·CVSS 8.1
CVE-2026-86117 [HIGH] CoolLabs Coolify up to 4.3.17 OAuth Callback assertion (EUVD-2026-71949)
A vulnerability was found in CoolLabs Coolify up to 4.3.17. It has been classified as critical. Affected is an unknown function of the component OAuth Callback Handler. The manipulation leads to reachable assertion.
This vulnerability is traded as CVE-2026-86117. It is possible to initiate the attack remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/coollabsio/coolifyhttps://github.com/coollabsio/coolify/blob/v4.3.17/app/Http/Controllers/OauthController.phphttps://github.com/coollabsio/coolify/blob/v4.3.17/routes/web.phphttps://github.com/geo-chen/oss/blob/main/coolify.mdhttps://www.vulncheck.com/advisories/coolify-through-4.3.17-oauth-account-takeover-via-unverified-email-matching
2026-09-05
Published