Authentication Bypass in Dokploy PaaS Affects Data Security
CVE-2026-72737
9.6CRITICAL
What is CVE-2026-72737?
The vulnerability in Dokploy allows authenticated users with backup permissions to manipulate backup operations affecting other organizations. Specifically, the methods for creating, updating, and restoring backups do not properly verify the client's organization context. This oversight can lead to unauthorized access to sensitive backup data, enabling attackers to extract S3 credentials from another organization's backup environment or disrupt multiple tenants' backup operations. This serious flaw emphasizes the necessity for strict access controls and verification processes in multi-tenant platforms.
Affected Version(s)
dokploy <= 0.29.8
