Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 05 Sep 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers can register a victim's email address on any enabled OAuth provider to obtain authenticated sessions as that user, bypassing password requirements and two-factor authentication. | |
| Title | Coolify through 4.3.17 OAuth Account Takeover via Unverified Email Matching | |
| First Time appeared |
Coollabs
Coollabs coolify |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:coollabs:coolify:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Coollabs
Coollabs coolify |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-05T09:59:07.349Z
Reserved: 2026-09-05T01:59:21.369Z
Link: CVE-2026-86117
No data.
Status : Received
Published: 2026-09-05T10:16:42.860
Modified: 2026-09-05T10:16:42.860
Link: CVE-2026-86117
No data.
OpenCVE Enrichment
Updated: 2026-09-05T11:30:05Z
