Coolercontrol: community verdicts
4 notable / known-exploited Coolercontrol CVEs the community has triaged.
- CVE-2026-5208HIGH 8.2Real · low riskEPSS 1%
Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash commands in alert names
- CVE-2026-5301HIGH 7.6Real · low riskEPSS 0%
Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries
- CVE-2026-5302MED 6.3EPSS 0%
CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and send commands to the service via malicious websites
- CVE-2026-5300MED 5.9EPSS 0%
Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data via HTTP requests