PT-2026-96827 · Dokploy · Dokploy
CVE-2026-86059
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Dokploy versions prior to 0.29.13
Description
Organization members without Git provider access can retrieve plaintext provider credentials. This occurs because the protected procedures 'github.one', 'gitlab.one', 'gitea.one', and 'bitbucket.one' return full provider rows without applying an organization check or the
getAccessibleGitProviderIds function. Additionally, the 'application.one' route returns nested relations from findApplicationById containing GitHub App private keys, OAuth tokens, client secrets, webhook secrets, and app passwords, even when hasGitProviderAccess is false. A member with application read access or a provider identifier can bypass per-member provider assignment to access private repositories or manipulate external workflows.Recommendations
Update to version 0.29.13.
Exploit
Fix
Information Disclosure
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dokploy