PT-2026-69904 · Dokploy · Dokploy
CVE-2026-72863
·
Published
2026-08-10
·
Updated
2026-08-10
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dokploy versions prior to 0.29.13
Description
WebSocket handlers used for in-app terminals and log streamers authenticate sessions using the
validateRequest() function but fail to perform authorization. Because they do not consult the role and permission model enforced by tRPC procedures, any authenticated member can open an interactive shell in any container on the host. This includes the Dokploy container that mounts the Docker socket, potentially allowing an attacker to obtain root access on the host, escape the application, and cross tenant boundaries.Recommendations
Update to version 0.29.13.
Exploit
Fix
Improper Privilege Management
Missing Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dokploy