PT-2026-69882 · Dokploy · Dokploy

CVE-2026-72737

·

Published

2026-08-10

·

Updated

2026-08-13

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dokploy versions prior to 0.29.9
Description An issue exists where the application fails to verify if the destination.organizationId matches the ctx.session.activeOrganizationId when processing requests. This allows an authenticated member with backup permissions in one organization to manipulate the destinationId parameter to access resources of another organization. This can lead to the exposure of S3 accessKey and secretAccessKey via the getS3Credentials() function, unauthorized reading of backup objects, or the redirection and poisoning of backups across tenant boundaries. The affected API endpoints are 'backup.create', 'backup.update', and 'backup.restoreBackupWithLogs'.
Recommendations Update Dokploy to version 0.29.9 or later. As a temporary mitigation, restrict access to the 'backup.create', 'backup.update', and 'backup.restoreBackupWithLogs' endpoints to only highly trusted administrators.

Exploit

Fix

Missing Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72737
GHSA-56QV-89FQ-3H2Q

Affected Products

Dokploy