<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>Dokploy CVEs · CVE Brief</title>
    <link>https://cvebrief.com/archive/cves/vendor/dokploy/</link>
    <atom:link href="https://cvebrief.com/feeds/vendor/dokploy.xml" rel="self" type="application/rss+xml"/>
    <description>High and critical Dokploy vulnerabilities covered by CVE Brief, with independent analyst commentary.</description>
    <language>en-us</language>
    <lastBuildDate>Tue, 01 Sep 2026 12:00:00 GMT</lastBuildDate>
    <item>
      <title>CVE-2026-82954 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-82954/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-82954</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
      <description>Dokploy versions up to 0.29.7 contain a path traversal vulnerability in the writeTraefikConfigInPath function, allowing authenticated attackers to manipulate file paths remotely. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-45790 · CVSS 8.0 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-45790/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-45790</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 18 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy is a free, self-hostable Platform as a Service (PaaS) Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72733 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72733/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72733</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy versions before 0.29.13 are vulnerable to OS command injection in the backup restore functionality, allowing authenticated users to execute arbitrary commands within the host context. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72734 · CVSS 8.4 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72734/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72734</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy is a free, self-hostable Platform as a Service (PaaS) Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72735 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72735/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72735</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>An incomplete fix for a previous vulnerability allows authenticated users to perform OS command injection on remote servers managed by Dokploy through manipulated Traefik configuration settings. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72736 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72736/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72736</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy contains a command injection vulnerability in its registry credential and Docker Swarm management endpoints, allowing authenticated users to execute arbitrary commands on the host. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72737 · CVSS 9.6 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72737/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72737</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>A cross-tenant authorization bypass in Dokploy versions 0.29.8 and earlier allows authenticated users with backup permissions to access or poison backup data belonging to other organizations. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72738 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72738/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72738</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>An OS command injection vulnerability in the Dokploy backup endpoint allows authenticated users to execute arbitrary commands on the host server. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72740 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72740/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72740</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>An OS command injection vulnerability in Dokploy prior to 0.29.13 allows authenticated users with deployment permissions to execute arbitrary commands on the host by manipulating SSH host settings. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72862 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72862/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72862</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy contains an OS command injection vulnerability in its database service deployment functions, allowing authenticated users to execute arbitrary commands on the remote server. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72863 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72863/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72863</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy versions prior to 0.29.13 fail to enforce authorization checks on WebSocket handlers, allowing authenticated users to access interactive shells and escalate privileges to root. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72864 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72864/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72864</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy versions before 0.29.13 are vulnerable to a missing authorization flaw in the docker-container-terminal component, allowing authenticated users to gain a root shell in arbitrary containers. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72865 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72865/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72865</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy versions prior to 0.29.13 contain an OS command injection vulnerability in the compose update process, allowing authenticated users to execute arbitrary commands on the host system. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72866 · CVSS 8.8 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72866/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72866</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy is a free, self-hostable Platform as a Service (PaaS) Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72867 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72867/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72867</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy versions 0.29.3 through 0.29.12 are susceptible to OS command injection due to insufficient server-side validation of git branch fields during deployment operations. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72868 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72868/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72868</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy allows a low-privileged member to execute arbitrary OS commands as root by injecting malicious input into the rclone configuration fields during test connection operations. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72869 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72869/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72869</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>An OS command injection vulnerability in Dokploy prior to 0.29.13 allows authenticated users with backup permissions to execute arbitrary commands in the host context via crafted database names. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72870 · CVSS 8.7 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72870/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72870</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy is a free, self-hostable Platform as a Service (PaaS) Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72871 · CVSS 7.5 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72871/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72871</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy is a free, self-hostable Platform as a Service (PaaS) Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72872 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72872/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72872</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy improperly validates Bitbucket repository fields, allowing authenticated users to inject arbitrary OS commands into git clone operations. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72874 · CVSS 8.7 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72874/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72874</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy is a free, self-hostable Platform as a Service (PaaS) Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72875 · CVSS 8.8 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72875/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72875</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy is a free, self-hostable Platform as a Service (PaaS) Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72876 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72876/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72876</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy versions before 0.29.13 contain an authorization bypass and OS command injection flaw, allowing authenticated users to manipulate server IDs and execute commands on other tenants&apos; servers. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72877 · CVSS 9.6 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72877/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72877</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy versions before 0.29.13 are vulnerable to OS command injection via the dockerImage field, allowing authenticated users to execute arbitrary commands on build hosts. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72878 · CVSS 9.6 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72878/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72878</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy prior to 0.29.13 is vulnerable to OS command injection via the backup and restore pipeline, allowing authenticated admins to execute arbitrary commands on the host machine. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72879 · CVSS 9.4 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72879/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72879</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy versions prior to 0.29.8 are vulnerable to OS command injection via the getRegistryCommands function, allowing authenticated users to execute arbitrary commands on the host server. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72880 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72880/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72880</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy versions before 0.29.13 contain an arbitrary file write and deletion vulnerability due to improper input validation in the certificate management service. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72882 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72882/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72882</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy versions 0.28.8 and earlier are vulnerable to OS command injection via the filePath parameter, allowing authenticated users to execute arbitrary commands on remote servers. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72883 · CVSS 8.8 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72883/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72883</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy is a free, self-hostable Platform as a Service (PaaS) Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72884 · CVSS 8.7 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72884/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72884</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy is a free, self-hostable Platform as a Service (PaaS) Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72886 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72886/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72886</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>An improper privilege management vulnerability in Dokploy allows authenticated users to escalate privileges and execute arbitrary scripts as root on the host machine. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72901 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72901/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72901</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy versions prior to 0.29.13 are susceptible to OS command injection via the volume backup functionality, allowing authenticated low-privilege users to execute commands with root-level impact. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-72902 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-72902/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-72902</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Dokploy versions before 0.29.13 are vulnerable to OS command injection via the registry testing functions, allowing authenticated users to execute arbitrary commands on the host or remote server. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-45629 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-45629/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-45629</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Sat, 30 May 2026 12:00:00 GMT</pubDate>
      <description>An OS command injection vulnerability in the Dokploy /listen-deployment WebSocket endpoint allows authenticated users to execute arbitrary commands on remote servers. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-45631 · CVSS 10.0 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-45631/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-45631</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Sat, 30 May 2026 12:00:00 GMT</pubDate>
      <description>A hardcoded authentication secret in Dokploy allows unauthenticated attackers to forge JWTs, gain administrative access, and execute commands on the host system via SSH. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-45632 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-45632/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-45632</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Sat, 30 May 2026 12:00:00 GMT</pubDate>
      <description>A broken access control vulnerability in the Dokploy schedule router allows authenticated users to manage schedules belonging to other organizations, leading to RCE. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-45633 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-45633/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-45633</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Sat, 30 May 2026 12:00:00 GMT</pubDate>
      <description>Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint that allows authenticated users to execute arbitrary commands with root privileges. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-45661 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-45661/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-45661</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Sat, 30 May 2026 12:00:00 GMT</pubDate>
      <description>A path traversal vulnerability in Dokploy allows authenticated users to write arbitrary files to the host or remote servers during application deployment, leading to full system compromise. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-45662 · CVSS 8.8 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-45662/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-45662</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Sat, 30 May 2026 12:00:00 GMT</pubDate>
      <description>Dokploy is a free, self-hostable Platform as a Service (PaaS) Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-45663 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-45663/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-45663</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Sat, 30 May 2026 12:00:00 GMT</pubDate>
      <description>Dokploy contains a command injection vulnerability in its Docker file upload functionality that allows authenticated users to execute arbitrary OS commands. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-27130 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-27130/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-27130</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Tue, 19 May 2026 12:00:00 GMT</pubDate>
      <description>Dokploy 0.26.6 and below contain an OS command injection vulnerability in the appName parameter, allowing authenticated attackers to execute arbitrary commands with server-level privileges. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-24840 · CVSS 8.0 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-24840/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-24840</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Wed, 28 Jan 2026 12:00:00 GMT</pubDate>
      <description>Dokploy is a free, self-hostable Platform as a Service (PaaS) Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-24841 · CVSS 9.9 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2026-24841/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2026-24841</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Wed, 28 Jan 2026 12:00:00 GMT</pubDate>
      <description>Dokploy is a free, self-hostable Platform as a Service (PaaS). Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-53825 · CVSS 9.4 · dokploy</title>
      <link>https://cvebrief.com/cve/cve-2025-53825/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-dokploy-CVE-2025-53825</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/dokploy.png" medium="image" type="image/png"/>
      <pubDate>Mon, 14 Jul 2025 12:00:00 GMT</pubDate>
      <description>Dokploy is a free, self-hostable Platform as a Service (PaaS). Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
  </channel>
</rss>
