CVE detail
CVE-2026-15507
A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing authorization. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 5
- within the 30d window
- Peak daily
- 5
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://vuldb.com/vuln/377836/ctivuldb.com
No excerpt available.
Exploitvuldb.comJul 12, 2026, 10:16 PM - https://vuldb.com/vuln/377836vuldb.com
No excerpt available.
Exploitvuldb.comJul 12, 2026, 10:16 PM - https://vuldb.com/submit/845670vuldb.com
No excerpt available.
Exploitvuldb.comJul 12, 2026, 10:16 PM - https://vuldb.com/cve/CVE-2026-15507vuldb.com
No excerpt available.
Exploitvuldb.comJul 12, 2026, 10:16 PM - https://github.com/lakshayyverma/CVE-Discovery/blob/main/coolify-resource-policy-stubs.zipgithub.com
No excerpt available.
Exploitgithub.comJul 12, 2026, 10:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16215CVSS 5.5 · Medium
A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Handler. Performing a manipulati…
- CVE-2026-16197CVSS 2.1 · Low
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go o…
- CVE-2026-16123CVSS 2.1 · Low
A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.…
- CVE-2026-55518CVSS 9.6 · Critical
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and G…
- CVE-2026-16017CVSS 2.1 · Low
A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file tools/tool_cron.go of the component cron Chat Tool. The manip…
- CVE-2026-15752CVSS 5.5 · Medium
A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the compon…