CVE-2026-45790
8.0Dokploy · dokploy
Dokploy versions prior to 0.29.6 are vulnerable to improper privilege management, allowing authenticated users to perform unauthorized actions.
Executive summary
An improper privilege management vulnerability in Dokploy allows authenticated users to escalate their access and potentially gain control over the platform.
Vulnerability
The software suffers from improper privilege management (CWE-269), which permits an authenticated user to perform actions outside of their assigned security context. This flaw occurs during standard application operations and requires the user to be authenticated.
Business impact
This vulnerability allows for unauthorized access to administrative functions, which could lead to full platform compromise. With a CVSS score of 8.0, the impact on business operations, data integrity, and service availability is high.
Remediation
Immediate Action: Upgrade your Dokploy installation to version 0.29.6 or newer to remediate this privilege management flaw.
Proactive Monitoring: Review audit logs for unauthorized access attempts to administrative panels or unexpected modifications to platform configurations.
Compensating Controls: Restrict access to the Dokploy administrative dashboard to a limited, trusted set of users via network-level controls or VPNs.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this issue necessitates an immediate update. Organizations should ensure that all instances of Dokploy are patched to at least version 0.29.6 to eliminate the risk of unauthorized privilege escalation.