Remote Code Execution Vulnerability in Dokploy PaaS
CVE-2026-45632

9.9CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-45632?

In versions 0.26.7 and earlier of the Dokploy Platform as a Service (PaaS), a flaw in the schedule router allows authenticated users to bypass organization and role checks. This enables them to create, update, run, or delete schedules belonging to other organizations if they have the scheduleId or serverId. The vulnerable types of schedules can execute scripts either on the Dokploy host or on remote servers, leading to potential compromise of sensitive environments.

Affected Version(s)

dokploy <= 0.26.7

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.