WebSocket Access Control Vulnerability in Dokploy Platform
CVE-2026-72866
8.8HIGH
What is CVE-2026-72866?
Dokploy is a self-hostable Platform as a Service (PaaS) that had a vulnerability in its WebSocket handler. Prior to version 0.29.13, the handler authenticated sessions but lacked proper authorization checks for server access. This allowed authenticated users to connect to an unauthorized terminal session by selecting the special serverId=local branch. As a result, users could gain access to an interactive terminal on the Dokploy host without having the requisite organization role or server access permissions. The issue has been addressed in version 0.29.13.
Affected Version(s)
dokploy < 0.29.13
