Directory Traversal Vulnerability in Dokploy Platform as a Service
CVE-2026-72880

9.9CRITICAL

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72880?

Dokploy, a self-hostable Platform as a Service (PaaS), has a directory traversal vulnerability due to improper handling of the client-supplied 'certificatePath' in its API. An authenticated user with permissions to create or delete certificates could exploit this flaw to write malicious certificate content outside the designated directory or to delete content from paths that should not be accessible. This issue was addressed in version 0.29.13, ensuring that user inputs are properly confined to prevent unauthorized access or modification of files.

Affected Version(s)

dokploy < 0.29.13

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.