PT-2026-69940 · Dokploy · Dokploy
CVE-2026-72886
·
Published
2026-08-10
·
Updated
2026-08-10
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dokploy versions 0.29.2 through 0.29.12
Description
In the
apps/dokploy/server/api/routers/schedule.ts file, the schedule.create and schedule.update endpoints derive the serviceId from the applicationId or composeId. Due to an error where the owner/admin host-schedule gate is only executed in the alternative branch, a member with access to a single application can attach its applicationId to a dokploy-server schedule. This allows the user to execute a supplied script as root via the schedule.runManually function.Recommendations
Update to version 0.29.13.
Exploit
Fix
Improper Privilege Management
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dokploy