Coolercontrol is a hardware-monitoring and fan-control daemon for Linux systems, with its primary exposure centered on the coolercontrold service. The recurring weakness classes, including cross-site scripting, OS command injection, missing authentication for critical functions, and permissive cross-domain policies, reflect input-handling and access-control gaps in a service that often runs with elevated privileges and network accessibility. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Coolercontrol over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-5300CRITICAL Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data via HTTP requests | Apr 8, 2026 | 9.1 | 37 | NO | NO |
CVE-2026-5302HIGH CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and send commands to the service via malicious websites | Apr 8, 2026 | 8.1 | 28 | NO | NO |
CVE-2026-5208HIGH Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash commands in alert names | Apr 8, 2026 | 7.2 | 28 | NO | NO |
CVE-2026-5301MEDIUM Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries | Apr 8, 2026 | 6.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Coolercontrol.
Media articles that mention a CVE ID that affects a product developed by Coolercontrol — matched by CVE ID, not by vendor name.