CVE-2026-72737

9.6

Dokploy · dokploy

A cross-tenant authorization bypass in Dokploy versions 0.29.8 and earlier allows authenticated users with backup permissions to access or poison backup data belonging to other organizations.

Executive summary

A critical authorization bypass in Dokploy allows authenticated users to access or manipulate sensitive backup data across different organizational boundaries.

Vulnerability

The application fails to verify that the destinationId provided in backup API requests belongs to the authenticated user's organization. This allows an attacker with legitimate backup permissions to access or poison S3 credentials and data belonging to other tenants.

Business impact

With a CVSS score of 9.6, this vulnerability permits severe cross-tenant data exposure and manipulation. An attacker can exfiltrate sensitive backup data, including S3 access keys, or poison backups, which could lead to widespread data loss or unauthorized access across the entire Platform as a Service (PaaS) environment.

Remediation

Immediate Action: Update Dokploy to version 0.29.9 or later to incorporate the necessary cross-organization authorization checks.

Proactive Monitoring: Audit access logs for backup-related API requests and monitor for anomalous cross-tenant activity or unauthorized attempts to access backup destinations.

Compensating Controls: Restrict administrative access to backup management features to a minimal set of trusted users until the patch can be fully deployed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability is highly severe for any multi-tenant deployment, as it breaks the fundamental isolation between organizations. It is imperative to update to the latest version immediately to restore proper authorization controls and protect tenant data integrity.

More Dokploy CVEs