CVE-2026-45790

8.0

Dokploy · dokploy

Dokploy versions prior to 0.29.6 are vulnerable to improper privilege management, allowing authenticated users to perform unauthorized actions.

Executive summary

An improper privilege management vulnerability in Dokploy allows authenticated users to escalate their access and potentially gain control over the platform.

Vulnerability

The software suffers from improper privilege management (CWE-269), which permits an authenticated user to perform actions outside of their assigned security context. This flaw occurs during standard application operations and requires the user to be authenticated.

Business impact

This vulnerability allows for unauthorized access to administrative functions, which could lead to full platform compromise. With a CVSS score of 8.0, the impact on business operations, data integrity, and service availability is high.

Remediation

Immediate Action: Upgrade your Dokploy installation to version 0.29.6 or newer to remediate this privilege management flaw.

Proactive Monitoring: Review audit logs for unauthorized access attempts to administrative panels or unexpected modifications to platform configurations.

Compensating Controls: Restrict access to the Dokploy administrative dashboard to a limited, trusted set of users via network-level controls or VPNs.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this issue necessitates an immediate update. Organizations should ensure that all instances of Dokploy are patched to at least version 0.29.6 to eliminate the risk of unauthorized privilege escalation.

More Dokploy CVEs