Unrated severityNVD Advisory· Published Jul 12, 2026· Updated Jul 13, 2026
coollabsio Coolify Policy Policies authorization
CVE-2026-15507
Description
A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing authorization. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected products
1- Range: <=4.1.1
Patches
Vulnerability mechanics
References
5- github.com/lakshayyverma/CVE-Discovery/blob/main/coolify-resource-policy-stubs.zipmitreexploit
- vuldb.com/cve/CVE-2026-15507mitrethird-party-advisory
- vuldb.com/submit/845670mitrethird-party-advisory
- vuldb.com/vuln/377836mitrevdb-entry
- vuldb.com/vuln/377836/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.