Vulnerability in Dokploy PaaS Affects User Credential Security
CVE-2026-86059
9.6CRITICAL
What is CVE-2026-86059?
Dokploy is a free, self-hostable PaaS that experienced a significant access control flaw allowing organization members without Git provider permissions to access sensitive plaintext credentials through several integration routes. As a result, unauthorized users could view critical information such as GitHub App private keys, OAuth tokens, and other authentication secrets that should have been restricted. This vulnerability stems from the failure to apply necessary access checks in the relevant API calls, enabling potential misuse of credentials to manipulate private repositories and workflows without proper authorization. The issue was addressed in version 0.29.13.
Affected Version(s)
dokploy < 0.29.13
