Security Digest: July 7, 2026 - 20 Critical Vulnerabilities
Today’s most urgent risk is concentrated in Coolify, where a cluster of critical and high-severity flaws can lead to cross-tenant access, command injection, and remote code execution on managed servers. We are also tracking a WordPress RCE in WPFunnels, a 389 Directory Server denial-of-service, and authorization/path traversal issues in SSSD and Ontime.
· 13 min read
July 7, 2026 Security Alert: 20 Critical Vulnerabilities Demand Immediate Action
Executive Summary
Today’s most urgent risk is concentrated in Coolify, where a cluster of critical and high-severity flaws can lead to cross-tenant access, command injection, and remote code execution on managed servers. We are also tracking a WordPress RCE in WPFunnels, a 389 Directory Server denial-of-service, and authorization/path traversal issues in SSSD and Ontime.
Act now: prioritize emergency patching, disable exposed management features where possible, and assume any unpatched Coolify instance is at high risk of takeover. For WordPress sites using WPFunnels, treat enabled logging as a live exploitation condition until patched.
Critical Vulnerabilities
CVE-2026-34037: Coolify cloneTo() cross-tenant resource cloning
- Impact: Authenticated attackers can clone resources into other teams’ destinations and access cross-tenant resources.
- Affected Systems: Coolify prior to
4.0.0-beta.464. - Immediate Action: Upgrade Coolify immediately and review team/resource permissions.
- Mitigation: Patch to
4.0.0-beta.464or later; restrict authenticated user roles until verified.
CVE-2026-34047: Coolify terminal WebSocket authorization bypass
- Impact: Attackers may reach terminal functionality outside their scope and potentially execute commands.
- Affected Systems: Coolify prior to
4.0.0-beta.471. - Immediate Action: Patch immediately and audit terminal access paths.
- Mitigation: Upgrade to
4.0.0-beta.471; disable terminal access for non-admins if possible.
CVE-2026-34048: Coolify terminal routes missing terminal authorization
- Impact: Low-privileged team members can connect to terminal routes and execute commands on team servers.
- Affected Systems: Coolify prior to
4.0.0-beta.471. - Immediate Action: Treat as an active RCE risk and patch now.
- Mitigation: Upgrade to
4.0.0-beta.471; review team membership and revoke unnecessary access.
CVE-2026-14345: WPFunnels log file RCE via postData
- Impact: Unauthenticated attackers can inject code that executes when an admin opens a polluted log file.
- Affected Systems: WPFunnels up to and including
3.12.7, with logs enabled. - Immediate Action: Disable logs now, update the plugin, and inspect for suspicious log content.
- Mitigation: Upgrade beyond
3.12.7; keep Enable Logs off until confirmed safe.
CVE-2026-34152: Coolify deployment command injection via heredoc transport
- Impact: Authenticated attackers can inject shell statements during deployment.
- Affected Systems: Coolify prior to
4.0.0-beta.471. - Immediate Action: Pause deployments from untrusted users and patch immediately.
- Mitigation: Upgrade to
4.0.0-beta.471; review pre/post-deployment commands.
CVE-2026-34168: Coolify LocalPersistentVolume name command injection
- Impact: Attackers can execute commands on managed servers when a resource is deleted.
- Affected Systems: Coolify prior to
4.0.0-beta.471. - Immediate Action: Block untrusted volume creation and patch.
- Mitigation: Upgrade to
4.0.0-beta.471; review storage naming controls.
CVE-2026-34035: Coolify log drain secret/environment command injection
- Impact: Authenticated users can inject commands on the host.
- Affected Systems: Coolify prior to
4.0.0-beta.466. - Immediate Action: Patch and rotate any exposed log drain secrets.
- Mitigation: Upgrade to
4.0.0-beta.466; review shell-interpolated settings.
CVE-2026-42143: Coolify persistent volume shell injection
- Impact: Authenticated members can execute commands as root during volume operations.
- Affected Systems: Coolify prior to
4.0.0-beta.471. - Immediate Action: Restrict volume operations and patch immediately.
- Mitigation: Upgrade to
4.0.0-beta.471; validate volume names server-side.
CVE-2026-42200: Coolify PostgreSQL init script path handling flaw
- Impact: Authenticated attackers can write outside the intended directory and achieve code execution.
- Affected Systems: Coolify prior to
4.0.0-beta.474. - Immediate Action: Patch and inspect database initialization workflows.
- Mitigation: Upgrade to
4.0.0-beta.474; review file path restrictions.
CVE-2026-34158: Coolify Docker command breakout via quoted settings
- Impact: Attackers can escape quoted context and execute arbitrary host commands during deployments.
- Affected Systems: Coolify prior to
4.0.0-beta.469. - Immediate Action: Restrict app-setting edits and patch now.
- Mitigation: Upgrade to
4.0.0-beta.469; audit custom build/start commands.
CVE-2026-34058: Coolify unmanaged container control command injection
- Impact: Any authenticated team member can execute arbitrary OS commands on remote servers.
- Affected Systems: Coolify prior to
4.0.0-beta.471. - Immediate Action: Disable or tightly restrict unmanaged container controls.
- Mitigation: Upgrade to
4.0.0-beta.471; monitor SSH command execution.
CVE-2026-34034: Coolify Sentinel token shell injection
- Impact: Authenticated users with Sentinel access can execute commands when Sentinel restarts.
- Affected Systems: Coolify prior to
4.0.0-beta.466. - Immediate Action: Patch and review Sentinel settings immediately.
- Mitigation: Upgrade to
4.0.0-beta.466; rotate sensitive tokens if exposed.
CVE-2026-34057: Coolify database import container-name injection
- Impact: Authenticated users can inject commands through database import settings.
- Affected Systems: Coolify prior to
4.0.0-beta.471. - Immediate Action: Limit database import access and patch.
- Mitigation: Upgrade to
4.0.0-beta.471; validate container names before use.
CVE-2026-11610: 389 Directory Server heap overflow in SASL I/O
- Impact: Authenticated attackers can crash the directory server, causing denial of service.
- Affected Systems: 389-ds-base and downstream FreeIPA/Red Hat Identity Management deployments using the vulnerable SASL I/O path.
- Immediate Action: Prioritize patching and watch for unexpected LDAP disconnects or crashes.
- Mitigation: Apply vendor updates as soon as available; restrict authenticated network access where possible.
CVE-2026-8377: Access Control System (GKS) authorization bypass
- Impact: Attackers may access common resource data without authorization.
- Affected Systems: Access Control System (GKS) before version 2.
- Immediate Action: Upgrade immediately and review exposed APIs.
- Mitigation: Move to version 2 or later; restrict access to trusted users only.
CVE-2026-14476: SSSD AD GPO path traversal
- Impact: Attackers with GPO management access can write files as root and may trigger authentication bypass.
- Affected Systems: SSSD AD GPO provider on affected RHEL-based systems.
- Immediate Action: Patch and review GPO management privileges now.
- Mitigation: Apply vendor fixes; keep SELinux enforcing and monitor for abnormal Kerberos config changes.
CVE-2026-34171: Coolify invitation URL can trigger password reset
- Impact: Attackers can reset a victim account password to a predictable value after a crafted link is visited.
- Affected Systems: Coolify prior to
4.0.0-beta.471. - Immediate Action: Warn users not to click invitation links and patch immediately.
- Mitigation: Upgrade to
4.0.0-beta.471; invalidate suspicious invitations.
CVE-2026-34044: Coolify log access across team boundaries
- Impact: Authenticated users can access logs from other teams by supplying a victim UUID.
- Affected Systems: Coolify prior to
4.0.0-beta.466. - Immediate Action: Patch and review log access permissions.
- Mitigation: Upgrade to
4.0.0-beta.466; audit log exposure for tenant separation.
CVE-2026-5799: Ontime authorization bypass via user-controlled key
- Impact: Attackers may exploit trusted identifiers to bypass authorization controls.
- Affected Systems: Ontime through
04052026. - Immediate Action: Update immediately and review any systems using trusted identifier flows.
- Mitigation: Apply vendor guidance; rotate or invalidate exposed identifiers if possible.
CVE-2026-5730: Ontime authorization bypass via user-controlled key
- Impact: Similar trusted-identifier abuse may let attackers bypass access controls.
- Affected Systems: Ontime through
04052026. - Immediate Action: Patch and restrict access to identifier-based endpoints.
- Mitigation: Apply the latest vendor release and verify authorization checks.
What to Do Now
- Patch Coolify first. Multiple flaws allow command execution, cross-tenant access, and privilege escalation. Treat any unpatched instance as urgent.
- Disable risky features temporarily. Turn off logs in WPFunnels, restrict terminal access, and limit deployment/custom command features in Coolify until patched.
- Review exposed admin and team permissions. Remove unnecessary access to servers, terminal tools, volume operations, Sentinel settings, and database import features.
- Check for compromise. Search for unexpected shell commands, new users, unknown SSH activity, suspicious log entries, and modified database init files.
- Verify versions. Confirm Coolify is at least
4.0.0-beta.474where applicable, WPFunnels is beyond3.12.7, and vendor patches are applied for 389-ds-base, SSSD, GKS, and Ontime.
Verification steps: inventory all exposed instances, confirm package versions, review recent deployments and volume operations, and validate that authorization middleware is enforced on management routes.
Monitoring recommendations: alert on new shell execution, unexpected file writes, repeated invitation-link visits, terminal/WebSocket connections, LDAP crashes, and any cross-tenant log or resource access.
Related Resources
- Internal: See the upcoming internal advisory on Coolify emergency hardening.
- Internal: See the upcoming internal checklist for WordPress plugin RCE exposure.
- Official vendor advisories: Coolify release notes, WPFunnels security update, 389 Directory Server advisories, Red Hat SSSD guidance, and Ontime/GKS vendor notices.