Unauthorized Access Vulnerability in Dokploy PaaS by Dokploy
CVE-2026-45631
10CRITICAL
What is CVE-2026-45631?
Dokploy, a free self-hostable Platform as a Service (PaaS), has a security flaw that arises from a hardcoded fallback for BETTER_AUTH_SECRET ('better-auth-secret-123456789'). This allows unauthenticated attackers to forge email verification JSON Web Tokens (JWTs), gain unauthorized administrative access, and execute arbitrary commands on the host system via the integrated SSH terminal. The issue is addressed in version 0.29.3. For further details and remediation measures, refer to the official advisory.
Affected Version(s)
dokploy >= 0.27.0, < 0.29.3
