WebSocket Access Control Vulnerability in Dokploy Platform
CVE-2026-72866

8.8HIGH

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72866?

Dokploy is a self-hostable Platform as a Service (PaaS) that had a vulnerability in its WebSocket handler. Prior to version 0.29.13, the handler authenticated sessions but lacked proper authorization checks for server access. This allowed authenticated users to connect to an unauthorized terminal session by selecting the special serverId=local branch. As a result, users could gain access to an interactive terminal on the Dokploy host without having the requisite organization role or server access permissions. The issue has been addressed in version 0.29.13.

Affected Version(s)

dokploy < 0.29.13

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.