Authentication Bypass in Dokploy PaaS Affects Data Security
CVE-2026-72737

9.6CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72737?

The vulnerability in Dokploy allows authenticated users with backup permissions to manipulate backup operations affecting other organizations. Specifically, the methods for creating, updating, and restoring backups do not properly verify the client's organization context. This oversight can lead to unauthorized access to sensitive backup data, enabling attackers to extract S3 credentials from another organization's backup environment or disrupt multiple tenants' backup operations. This serious flaw emphasizes the necessity for strict access controls and verification processes in multi-tenant platforms.

Affected Version(s)

dokploy <= 0.29.8

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.