Penetration Testing Blog

Stay informed with the latest cybersecurity insights, penetration testing best practices, and security tips from our team.

CVE-2026-48742 CVSS 8.8 High Security Research
Security Research

Authorization Temporarily Disabled: The Comment That Opened Coolify to Cross-Team IDOR

Every app/Policies/ file in Coolify had the same comment: "Authorization temporarily disabled." That comment was live in production. Any authenticated user on a shared Coolify instance could access, modify, and redeploy services belonging to other teams — including container image swaps that led to code execution. CVSS 8.8 High.

Read More