Arbitrary Command Execution Vulnerability in Dokploy Platform as a Service
CVE-2026-72881

6.4MEDIUM

Key Information:

Vendor

Dokploy

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72881?

A vulnerability exists in the Dokploy Platform as a Service that allows an authenticated administrator with database creation and backup configuration privileges to use crafted database configuration fields, leading to arbitrary command execution within various database container environments such as PostgreSQL, MariaDB, MySQL, MongoDB, and LibSQL. This exploitation can expose sensitive database credentials and potentially allow for an escape from container limitations. The issue has been addressed in Dokploy version 0.29.13.

Affected Version(s)

dokploy < 0.29.13

References

CVSS V4

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.