PT-2026-69882 · Dokploy · Dokploy
CVE-2026-72737
·
Published
2026-08-10
·
Updated
2026-08-13
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Dokploy versions prior to 0.29.9
Description
An issue exists where the application fails to verify if the
destination.organizationId matches the ctx.session.activeOrganizationId when processing requests. This allows an authenticated member with backup permissions in one organization to manipulate the destinationId parameter to access resources of another organization. This can lead to the exposure of S3 accessKey and secretAccessKey via the getS3Credentials() function, unauthorized reading of backup objects, or the redirection and poisoning of backups across tenant boundaries. The affected API endpoints are 'backup.create', 'backup.update', and 'backup.restoreBackupWithLogs'.Recommendations
Update Dokploy to version 0.29.9 or later.
As a temporary mitigation, restrict access to the 'backup.create', 'backup.update', and 'backup.restoreBackupWithLogs' endpoints to only highly trusted administrators.
Exploit
Fix
Missing Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dokploy