External risk intelligence

Coolify OAuth Callback Authentication Bypass Leads to Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-86117

Coolify is an open-source, self-hosted platform used as an application deployment and management service. Because it functions as a web-based dashboard and control plane for managing services, it is commonly deployed as an internet-facing administrative portal, making its OAuth callback handlers and authentication endpoints reachable from the public internet in typical deployments.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects Coolify software, allowing attackers to gain unauthorized access to user accounts by exploiting a weakness in how the system handles external login providers. The issue bypasses standard security measures like passwords and multi-factor authentication if an attacker can link a victim's email address to a compromised or attacker-controlled external account. The main concern is confirming relevance and exposure, as the method of exploitation requires specific conditions.

  • Bypasses authentication using external logins.
  • Important for preventing unauthorized account access.
  • Confirm relevance and exposure for leadership.

Attack Path

How an attacker could exploit the issue

An attacker could gain access to a user's account by exploiting a vulnerability in the OAuth callback handler. This would involve an attacker registering a victim's email address with an OAuth provider and then using that to bypass Coolify's authentication, effectively taking over the user's account.

  • Requires attacker to control a victim's email.
  • Triggers on OAuth callback with unverified email.
  • Enables unauthenticated account takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow attackers to bypass authentication and gain access to user accounts by registering a victim's email address with an OAuth provider. This bypasses password and two-factor authentication requirements when supported by the advisory.

  • User accounts could be compromised.
  • Attackers could impersonate users via email.
  • Unauthorized access to services may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The application owner is responsible for addressing this vulnerability, as it impacts the authentication flow within the Coolify platform. The immediate priority is to identify all instances of Coolify, confirm their exposure, and determine business criticality to prioritize remediation efforts.

  • Application owners should manage this vulnerability.
  • Verify external access and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Coolify?

Coolify is an open-source, self-hosted platform that serves as an all-in-one dashboard for deploying and managing applications, databases, and services. It functions as a centralized control plane for developers and system administrators to streamline infrastructure management, often acting as the primary management portal for their hosted environments.

How does CVE-2026-86117 enable an authentication bypass?

This vulnerability, classified as Improper Authentication (CWE-287), exists in the OAuth callback handler. The software incorrectly trusts email addresses provided during external login flows without verifying them against the identity provider's secure assertions. Because it fails to bind the OAuth identity to the account, an attacker can log in as any existing user simply by using that user's email address.

What must an attacker do to trigger this vulnerability?

To exploit this, an attacker must have control over an account on an OAuth provider that uses a victim's email address. The flaw does not trigger if the OAuth integration is disabled, nor does it affect users who do not rely on OAuth providers for account access. It specifically exploits the logic failure during the callback phase of the authentication process.

Do I need to worry if my Coolify instance is internal?

Halo Surface Signal indicates that Coolify is commonly deployed as an internet-facing administrative portal, which makes its authentication endpoints reachable from the public internet in typical setups. If your instance is not exposed to the internet, the risk may be lower; however, you should still evaluate access controls, as any reachable endpoint using affected OAuth configurations is vulnerable.

What is the first step to address this issue?

The priority is to locate all active Coolify instances within your infrastructure and assess their authentication configurations. Determine if you have enabled OAuth providers and verify which services are exposed to network traffic. Consult the official project documentation or repository for updates and guidance on securing your deployment, while restricting access to administrative interfaces until you are confident in your mitigation path.

References