Authorization Bypass (IDOR)Weakness · CWE-639

CVE-2026-57498

CRITICAL · 9.6 CVSS v3.1 Published 2026-06-29
Mitigation only
No fix yet — a mitigation exists. There is no fixed release. A documented workaround reduces exposure in the meantime.
See remediation →
100/100
Remediation priority · Urgent
Remotely reachable Zero-click 7 weeks old

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any operation. However, multiple Livewire web UI components accept server_id and destination_uuid from URL query parameters without any team ownership validation, allowing cross-team resource deployment. This vulnerability is fixed in 4.0.0-beta.474.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

Livewire web UI components accept server_id and destination_uuid from URL query parameters without validating team ownership, allowing authenticated users to deploy resources to servers belonging to other teams, unlike API controllers which properly enforce Server::whereTeamId($teamId) checks.

MitigationUpgrade Coolify to version 4.0.0-beta.474 or later which adds proper team ownership validation to the affected Livewire components.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
Low
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Check your Coolify version
    Access the Coolify admin panel or run the version command (e.g., `coolify --version` or check the UI footer). Compare the installed version against 4.0.0-beta.474.
    Affected if The installed version is lower than 4.0.0-beta.474.
  2. Identify Livewire web UI endpoints
    Review your Coolify application's routes, particularly those handling server and deployment operations. Look for Livewire component routes that accept query parameters.
    Affected if Livewire components that handle server_id or destination_uuid parameters are present in the application.
  3. Inspect the affected query parameters
    Examine routes or controllers that handle server_id and destination_uuid in URL query strings. Check if these parameters are used in deployment-related Livewire components.
    Affected if URLs containing server_id or destination_uuid query parameters are processed without team ownership validation.
  4. Verify team ownership validation in Livewire components
    Review the Livewire component code that processes server_id and destination_uuid. Look for Server::whereTeamId($teamId) or equivalent team ownership checks before allowing deployment operations.
    Affected if The Livewire components lack proper team ownership validation (unlike the API controllers which include Server::whereTeamId($teamId) checks).

You are affected if your Coolify version is below 4.0.0-beta.474 and your Livewire web UI components accept server_id or destination_uuid from URL query parameters without validating that the authenticated user's team owns the referenced resources.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Mitigation available No clean upgrade yet — mitigate in the meantime
Mitigation

Upgrade Coolify to version 4.0.0-beta.474 or later which adds proper team ownership validation to the affected Livewire components.

Recommended fix High confidence

4.0.0-beta.474

  1. 1. Backup your current Coolify installation and database before upgrading.
  2. 2. Check your current Coolify version to confirm it is prior to 4.0.0-beta.474.
  3. 3. Upgrade Coolify to version 4.0.0-beta.474 or later. The exact upgrade command depends on your installation method (e.g., docker-compose, npm, or the built-in update mechanism).
  4. 4. After upgrading, verify that the Livewire web UI components now properly validate team ownership for server_id and destination_uuid parameters.
  5. 5. Test cross-team resource access to confirm the IDOR vulnerability is mitigated.
Caveat This is a beta release (4.0.0-beta.474). Review the release notes for any breaking changes before upgrading production environments.

Generated from the published advisory — verify against the referenced sources before acting.

Have this fixed Scoped from the published advisory
  • Consultation2.0 h
  • Implementation8.0 h
  • Testing4.0 h
  • Review / QA2.0 h
16.0 hours of engineering $2,800
Get help mitigating

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $4,480.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2026-57498 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2026-57498 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data