Security Digest: July 7, 2026 - 20 Critical Vulnerabilities

Today’s most urgent risk is concentrated in Coolify, where a cluster of critical and high-severity flaws can lead to cross-tenant access, command injection, and remote code execution on managed servers. We are also tracking a WordPress RCE in WPFunnels, a 389 Directory Server denial-of-service, and authorization/path traversal issues in SSSD and Ontime.

· 13 min read

July 7, 2026 Security Alert: 20 Critical Vulnerabilities Demand Immediate Action

Executive Summary

Today’s most urgent risk is concentrated in Coolify, where a cluster of critical and high-severity flaws can lead to cross-tenant access, command injection, and remote code execution on managed servers. We are also tracking a WordPress RCE in WPFunnels, a 389 Directory Server denial-of-service, and authorization/path traversal issues in SSSD and Ontime.

Act now: prioritize emergency patching, disable exposed management features where possible, and assume any unpatched Coolify instance is at high risk of takeover. For WordPress sites using WPFunnels, treat enabled logging as a live exploitation condition until patched.

Critical Vulnerabilities

CVE-2026-34037: Coolify cloneTo() cross-tenant resource cloning

  • Impact: Authenticated attackers can clone resources into other teams’ destinations and access cross-tenant resources.
  • Affected Systems: Coolify prior to 4.0.0-beta.464.
  • Immediate Action: Upgrade Coolify immediately and review team/resource permissions.
  • Mitigation: Patch to 4.0.0-beta.464 or later; restrict authenticated user roles until verified.

CVE-2026-34047: Coolify terminal WebSocket authorization bypass

  • Impact: Attackers may reach terminal functionality outside their scope and potentially execute commands.
  • Affected Systems: Coolify prior to 4.0.0-beta.471.
  • Immediate Action: Patch immediately and audit terminal access paths.
  • Mitigation: Upgrade to 4.0.0-beta.471; disable terminal access for non-admins if possible.

CVE-2026-34048: Coolify terminal routes missing terminal authorization

  • Impact: Low-privileged team members can connect to terminal routes and execute commands on team servers.
  • Affected Systems: Coolify prior to 4.0.0-beta.471.
  • Immediate Action: Treat as an active RCE risk and patch now.
  • Mitigation: Upgrade to 4.0.0-beta.471; review team membership and revoke unnecessary access.

CVE-2026-14345: WPFunnels log file RCE via postData

  • Impact: Unauthenticated attackers can inject code that executes when an admin opens a polluted log file.
  • Affected Systems: WPFunnels up to and including 3.12.7, with logs enabled.
  • Immediate Action: Disable logs now, update the plugin, and inspect for suspicious log content.
  • Mitigation: Upgrade beyond 3.12.7; keep Enable Logs off until confirmed safe.

CVE-2026-34152: Coolify deployment command injection via heredoc transport

  • Impact: Authenticated attackers can inject shell statements during deployment.
  • Affected Systems: Coolify prior to 4.0.0-beta.471.
  • Immediate Action: Pause deployments from untrusted users and patch immediately.
  • Mitigation: Upgrade to 4.0.0-beta.471; review pre/post-deployment commands.

CVE-2026-34168: Coolify LocalPersistentVolume name command injection

  • Impact: Attackers can execute commands on managed servers when a resource is deleted.
  • Affected Systems: Coolify prior to 4.0.0-beta.471.
  • Immediate Action: Block untrusted volume creation and patch.
  • Mitigation: Upgrade to 4.0.0-beta.471; review storage naming controls.

CVE-2026-34035: Coolify log drain secret/environment command injection

  • Impact: Authenticated users can inject commands on the host.
  • Affected Systems: Coolify prior to 4.0.0-beta.466.
  • Immediate Action: Patch and rotate any exposed log drain secrets.
  • Mitigation: Upgrade to 4.0.0-beta.466; review shell-interpolated settings.

CVE-2026-42143: Coolify persistent volume shell injection

  • Impact: Authenticated members can execute commands as root during volume operations.
  • Affected Systems: Coolify prior to 4.0.0-beta.471.
  • Immediate Action: Restrict volume operations and patch immediately.
  • Mitigation: Upgrade to 4.0.0-beta.471; validate volume names server-side.

CVE-2026-42200: Coolify PostgreSQL init script path handling flaw

  • Impact: Authenticated attackers can write outside the intended directory and achieve code execution.
  • Affected Systems: Coolify prior to 4.0.0-beta.474.
  • Immediate Action: Patch and inspect database initialization workflows.
  • Mitigation: Upgrade to 4.0.0-beta.474; review file path restrictions.

CVE-2026-34158: Coolify Docker command breakout via quoted settings

  • Impact: Attackers can escape quoted context and execute arbitrary host commands during deployments.
  • Affected Systems: Coolify prior to 4.0.0-beta.469.
  • Immediate Action: Restrict app-setting edits and patch now.
  • Mitigation: Upgrade to 4.0.0-beta.469; audit custom build/start commands.

CVE-2026-34058: Coolify unmanaged container control command injection

  • Impact: Any authenticated team member can execute arbitrary OS commands on remote servers.
  • Affected Systems: Coolify prior to 4.0.0-beta.471.
  • Immediate Action: Disable or tightly restrict unmanaged container controls.
  • Mitigation: Upgrade to 4.0.0-beta.471; monitor SSH command execution.

CVE-2026-34034: Coolify Sentinel token shell injection

  • Impact: Authenticated users with Sentinel access can execute commands when Sentinel restarts.
  • Affected Systems: Coolify prior to 4.0.0-beta.466.
  • Immediate Action: Patch and review Sentinel settings immediately.
  • Mitigation: Upgrade to 4.0.0-beta.466; rotate sensitive tokens if exposed.

CVE-2026-34057: Coolify database import container-name injection

  • Impact: Authenticated users can inject commands through database import settings.
  • Affected Systems: Coolify prior to 4.0.0-beta.471.
  • Immediate Action: Limit database import access and patch.
  • Mitigation: Upgrade to 4.0.0-beta.471; validate container names before use.

CVE-2026-11610: 389 Directory Server heap overflow in SASL I/O

  • Impact: Authenticated attackers can crash the directory server, causing denial of service.
  • Affected Systems: 389-ds-base and downstream FreeIPA/Red Hat Identity Management deployments using the vulnerable SASL I/O path.
  • Immediate Action: Prioritize patching and watch for unexpected LDAP disconnects or crashes.
  • Mitigation: Apply vendor updates as soon as available; restrict authenticated network access where possible.

CVE-2026-8377: Access Control System (GKS) authorization bypass

  • Impact: Attackers may access common resource data without authorization.
  • Affected Systems: Access Control System (GKS) before version 2.
  • Immediate Action: Upgrade immediately and review exposed APIs.
  • Mitigation: Move to version 2 or later; restrict access to trusted users only.

CVE-2026-14476: SSSD AD GPO path traversal

  • Impact: Attackers with GPO management access can write files as root and may trigger authentication bypass.
  • Affected Systems: SSSD AD GPO provider on affected RHEL-based systems.
  • Immediate Action: Patch and review GPO management privileges now.
  • Mitigation: Apply vendor fixes; keep SELinux enforcing and monitor for abnormal Kerberos config changes.

CVE-2026-34171: Coolify invitation URL can trigger password reset

  • Impact: Attackers can reset a victim account password to a predictable value after a crafted link is visited.
  • Affected Systems: Coolify prior to 4.0.0-beta.471.
  • Immediate Action: Warn users not to click invitation links and patch immediately.
  • Mitigation: Upgrade to 4.0.0-beta.471; invalidate suspicious invitations.

CVE-2026-34044: Coolify log access across team boundaries

  • Impact: Authenticated users can access logs from other teams by supplying a victim UUID.
  • Affected Systems: Coolify prior to 4.0.0-beta.466.
  • Immediate Action: Patch and review log access permissions.
  • Mitigation: Upgrade to 4.0.0-beta.466; audit log exposure for tenant separation.

CVE-2026-5799: Ontime authorization bypass via user-controlled key

  • Impact: Attackers may exploit trusted identifiers to bypass authorization controls.
  • Affected Systems: Ontime through 04052026.
  • Immediate Action: Update immediately and review any systems using trusted identifier flows.
  • Mitigation: Apply vendor guidance; rotate or invalidate exposed identifiers if possible.

CVE-2026-5730: Ontime authorization bypass via user-controlled key

  • Impact: Similar trusted-identifier abuse may let attackers bypass access controls.
  • Affected Systems: Ontime through 04052026.
  • Immediate Action: Patch and restrict access to identifier-based endpoints.
  • Mitigation: Apply the latest vendor release and verify authorization checks.

What to Do Now

  1. Patch Coolify first. Multiple flaws allow command execution, cross-tenant access, and privilege escalation. Treat any unpatched instance as urgent.
  2. Disable risky features temporarily. Turn off logs in WPFunnels, restrict terminal access, and limit deployment/custom command features in Coolify until patched.
  3. Review exposed admin and team permissions. Remove unnecessary access to servers, terminal tools, volume operations, Sentinel settings, and database import features.
  4. Check for compromise. Search for unexpected shell commands, new users, unknown SSH activity, suspicious log entries, and modified database init files.
  5. Verify versions. Confirm Coolify is at least 4.0.0-beta.474 where applicable, WPFunnels is beyond 3.12.7, and vendor patches are applied for 389-ds-base, SSSD, GKS, and Ontime.

Verification steps: inventory all exposed instances, confirm package versions, review recent deployments and volume operations, and validate that authorization middleware is enforced on management routes.

Monitoring recommendations: alert on new shell execution, unexpected file writes, repeated invitation-link visits, terminal/WebSocket connections, LDAP crashes, and any cross-tenant log or resource access.

Related Resources

  • Internal: See the upcoming internal advisory on Coolify emergency hardening.
  • Internal: See the upcoming internal checklist for WordPress plugin RCE exposure.
  • Official vendor advisories: Coolify release notes, WPFunnels security update, 389 Directory Server advisories, Red Hat SSSD guidance, and Ontime/GKS vendor notices.

Keep reading