Arbitrary Command Execution Vulnerability in Dokploy Platform as a Service
CVE-2026-72881
6.4MEDIUM
What is CVE-2026-72881?
A vulnerability exists in the Dokploy Platform as a Service that allows an authenticated administrator with database creation and backup configuration privileges to use crafted database configuration fields, leading to arbitrary command execution within various database container environments such as PostgreSQL, MariaDB, MySQL, MongoDB, and LibSQL. This exploitation can expose sensitive database credentials and potentially allow for an escape from container limitations. The issue has been addressed in Dokploy version 0.29.13.
Affected Version(s)
dokploy < 0.29.13
