Unauthorized Access Vulnerability in Dokploy PaaS by Dokploy
CVE-2026-45631

10CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-45631?

Dokploy, a free self-hostable Platform as a Service (PaaS), has a security flaw that arises from a hardcoded fallback for BETTER_AUTH_SECRET ('better-auth-secret-123456789'). This allows unauthenticated attackers to forge email verification JSON Web Tokens (JWTs), gain unauthorized administrative access, and execute arbitrary commands on the host system via the integrated SSH terminal. The issue is addressed in version 0.29.3. For further details and remediation measures, refer to the official advisory.

Affected Version(s)

dokploy >= 0.27.0, < 0.29.3

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.