CVE-2026-72883

8.8

Dokploy · Dokploy

Dokploy is affected by a missing authorization vulnerability, which allows authenticated users to perform unauthorized actions within the platform.

Executive summary

A missing authorization vulnerability in Dokploy permits authenticated users to execute unauthorized operations, posing a high risk to the security of hosted applications.

Vulnerability

The software fails to properly enforce authorization checks, allowing an authenticated user to perform actions outside of their intended permissions scope.

Business impact

With a CVSS score of 8.8, this flaw could allow an attacker to gain excessive privileges, potentially leading to unauthorized modification or deletion of deployments, data, and system configurations. This threatens the integrity of all services managed through the Dokploy platform.

Remediation

Immediate Action: Update the Dokploy installation to version 0.29.13 or later immediately to resolve the authorization logic error.

Proactive Monitoring: Review application logs for unauthorized access attempts or suspicious configuration changes performed by lower-privileged user accounts.

Compensating Controls: Audit user permissions within the Dokploy dashboard to ensure that the principle of least privilege is strictly maintained.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Maintaining proper authorization is fundamental to the security of a platform as a service. It is highly recommended that all users upgrade to version 0.29.13 immediately to eliminate the risk of privilege escalation and unauthorized system management.

More Dokploy CVEs