CVE-2026-72866

8.8

Dokploy · dokploy

A missing authorization vulnerability in Dokploy allows authenticated users to perform unauthorized actions due to improper capability checks.

Executive summary

A missing authorization flaw in Dokploy allows authenticated attackers to bypass security controls, posing a high risk to system integrity.

Vulnerability

The software suffers from a missing authorization vulnerability (CWE-862) which allows an attacker with low privileges to perform unauthorized actions. The attack requires the user to be authenticated to the platform.

Business impact

Successful exploitation of this vulnerability allows an authenticated attacker to perform actions beyond their intended permission level, potentially leading to unauthorized data access, modification of system configurations, or service disruption. With a CVSS score of 8.8, this flaw represents a significant risk to the security posture of the affected PaaS environment.

Remediation

Immediate Action: Update the Dokploy installation to version 0.29.13 or later as specified in the official vendor release.

Proactive Monitoring: Review administrative access logs for suspicious account activity or requests originating from low-privileged user accounts that deviate from expected behavioral patterns.

Compensating Controls: Implement strict network access controls to limit the exposure of the management interface to trusted internal networks only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The vulnerability presents a high risk due to the potential for unauthorized administrative actions. Administrators should prioritize patching to version 0.29.13 immediately to eliminate the authorization bypass vector and secure the platform.

More Dokploy CVEs