Uncontrolled Session Authentication Flaw in Dokploy PaaS
CVE-2026-72863
9.9CRITICAL
What is CVE-2026-72863?
Dokploy, a free self-hostable Platform as a Service (PaaS), contains a vulnerability in its WebSocket handlers before version 0.29.13. The flaw arises from improper authorization of authenticated sessions. While Dokploy correctly identifies users through session validation, it fails to enforce role and permission checks during its interactions with in-app terminals and log streamers. This oversight enables authenticated users to open an interactive shell in any container, including the sensitive dokploy container that interfaces with the Docker socket, potentially compromising the host system and breaching tenant isolation.
Affected Version(s)
dokploy < 0.29.13
