CVE-2026-72871
7.5Dokploy · Dokploy
Dokploy contains a critical missing authentication vulnerability in its platform management functions, allowing unauthorized actors to perform administrative actions.
Executive summary
A critical authentication bypass vulnerability in Dokploy allows unauthenticated remote attackers to perform unauthorized actions on the platform, presenting a severe risk to system integrity.
Vulnerability
This is a missing authentication for critical function vulnerability (CWE-306). An unauthenticated remote attacker can interact with critical platform features without providing valid credentials.
Business impact
This vulnerability allows an attacker to gain unauthorized control over platform management, potentially leading to unauthorized deployment, configuration changes, or complete system compromise. With a CVSS score of 7.5, the impact on integrity is high, as the attacker can manipulate the platform state.
Remediation
Immediate Action: Upgrade all Dokploy instances to version 0.29.13 or later to enforce proper authentication checks for all critical functions.
Proactive Monitoring: Audit logs for unauthorized management actions or unexpected configuration changes that occurred prior to applying the patch.
Compensating Controls: Restrict access to the Dokploy management dashboard using VPNs or IP whitelisting to prevent exposure to the public internet until the update is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability is highly critical due to the presence of a proof-of-concept and the nature of the flaw. Immediate patching to version 0.29.13 is required to secure the platform against unauthorized administrative access.