User Authentication Vulnerability in Dokploy Platform as a Service
CVE-2026-45791
5.9MEDIUM
What is CVE-2026-45791?
Dokploy, a self-hostable Platform as a Service (PaaS), has a significant vulnerability in its user.update procedure. This issue pertains to the handling of account.password updates, whereby old session tokens remain valid for up to three days even after a password change. This flaw could allow an attacker to maintain unauthorized access if they have already compromised the session token. The vulnerability has been addressed in Dokploy version 0.29.6, which ensures that all session tokens are invalidated upon a password change, enhancing the overall security of the user accounts.
Affected Version(s)
dokploy < 0.29.6
