Uncontrolled Session Authentication Flaw in Dokploy PaaS
CVE-2026-72863

9.9CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72863?

Dokploy, a free self-hostable Platform as a Service (PaaS), contains a vulnerability in its WebSocket handlers before version 0.29.13. The flaw arises from improper authorization of authenticated sessions. While Dokploy correctly identifies users through session validation, it fails to enforce role and permission checks during its interactions with in-app terminals and log streamers. This oversight enables authenticated users to open an interactive shell in any container, including the sensitive dokploy container that interfaces with the Docker socket, potentially compromising the host system and breaching tenant isolation.

Affected Version(s)

dokploy < 0.29.13

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.