User Authentication Vulnerability in Dokploy Platform as a Service
CVE-2026-45791

5.9MEDIUM

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-45791?

Dokploy, a self-hostable Platform as a Service (PaaS), has a significant vulnerability in its user.update procedure. This issue pertains to the handling of account.password updates, whereby old session tokens remain valid for up to three days even after a password change. This flaw could allow an attacker to maintain unauthorized access if they have already compromised the session token. The vulnerability has been addressed in Dokploy version 0.29.6, which ensures that all session tokens are invalidated upon a password change, enhancing the overall security of the user accounts.

Affected Version(s)

dokploy < 0.29.6

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.