---
schema: 1
kind: vulnerability
title: "CVE-2026-34038 — Coolify: authenticated command injection to RCE and secrets exfiltration (CVSS 9.9)"
headline: "CVE-2026-34038 — Coolify: authenticated command injection to RCE and secrets exfiltration (CVSS 9.9)"
summary: "Coolify ships an emergency fix for a CVSS 9.9 authenticated command-injection RCE (CVE-2026-34038). Any org self-hosting the Coolify PaaS for CI/CD should patch to ≥ v4.0.0-beta.469 now: a user with only application \"write\" permission can inject OS commands via the dockerfile_location / pre_deployment_command deployment parameters and exfiltrate application secrets from deployment logs (coollabsio GHSA, 2026-07-02)."
discovered_at: "2026-07-03T04:48:14Z"
event_date: 2026-07-02
run_id: 2026-07-03-04ba8283
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - patch-available
regions:
  - global
sectors:
  - technology
entities: []
cves:
  - id: CVE-2026-34038
    cvss: "9.9"
    epss: null
    type: rce
    vector: zero-click
    auth: post-auth
    status:
      - patch-available
sources:
  - url: "https://github.com/coollabsio/coolify/security/advisories/GHSA-qqrq-r9h4-x6wp"
    publisher: coollabsio GHSA-qqrq-r9h4-x6wp
    role: primary
  - url: "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2182"
    publisher: BSI CERT-Bund WID-SEC-2026-2182
    role: corroborating
closed_sources: []
evidence:
  - quote: "An authenticated remote command injection vulnerability (CWE-78) in Coolify allows users with application 'write' permissions to achieve Remote Code Execution (RCE)"
    publisher: coollabsio GHSA-qqrq-r9h4-x6wp
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**If you self-host Coolify, patch to ≥ v4.0.0-beta.469 now** and rotate any secrets referenced in deployment environment variables that were reachable before patching — the flaw exfiltrates them via deployment logs. Restrict application \"write\" grants to trusted users given the permission-bypass path."
migrated_from: briefs/2026-07-03.md
---

Coolify — a widely used open-source self-hosted PaaS / deployment platform (a Heroku/Vercel alternative for organizations running their own CI/CD-to-production pipelines) — fixed a CWE-78 OS command-injection flaw (CVSS 3.1 9.9, `AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H`) in `ApplicationDeploymentJob.php`. The `dockerfile_location` and `pre_deployment_command` deployment parameters are passed to a shell without escaping, letting a user with only application "write" permission inject arbitrary OS commands (via `;`, `&&`, backticks) that execute on the underlying host during a deployment; because deployment logs capture command output, exploitation also exfiltrates the application's configured environment secrets ([coollabsio GHSA-qqrq-r9h4-x6wp, 2026-07-02](https://github.com/coollabsio/coolify/security/advisories/GHSA-qqrq-r9h4-x6wp)). The vendor advisory notes a separate permission-bypass means the attacker does not need explicit "deploy" rights — broad "write" access is enough. BSI CERT-Bund published WID-SEC-2026-2182 the same day citing the GHSA as origin ([BSI CERT-Bund, 2026-07-01](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2182)). Fixed in ≥ v4.0.0-beta.469; ≤ v4.0.0-beta.462 are affected. No in-the-wild exploitation is reported by the vendor or BSI, and the CVE is not yet NVD-enriched. Detection: audit deployment-job logs for shell metacharacters in `dockerfile_location`/`pre_deployment_command` submitted by non-admin write-scoped accounts, and flag unexpected child processes off the PHP-FPM/queue-worker tree during a deployment (T1059 / T1190). Hardening: patch, restrict "write" grants to trusted users, and rotate any secrets referenced in deployment env vars that were reachable before patching.
