Hardcoded Credentials Vulnerability in Dokploy PaaS
CVE-2026-24840
8HIGH
What is CVE-2026-24840?
Dokploy, a self-hostable Platform as a Service (PaaS), contains a vulnerability related to hardcoded credentials in its installation script. This issue impacts versions prior to 0.26.6, which utilize the same default database password, potentially exposing all Dokploy installations to unauthorized access. Users are encouraged to upgrade to version 0.26.6 to mitigate this risk. For further details and guidance, refer to the security advisory and the commit information.
Affected Version(s)
dokploy < 0.26.6
