Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-72886: Dokploy: Unauthorized users gain root access on the host
CVE-2026-72886
CVE-2026-72886
Summary
A security flaw in Dokploy allowed non-admin users to gain root access on the host by exploiting a scheduling feature. This could have allowed unauthorized users to execute malicious scripts with elevated privileges. Users are advised to update to version 0.29.13 or later to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| dokploy | dokploy | >= 0.29.2, < 0.29.13 |
Original title
Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632)
Original description
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/admin host-schedule gate only in the alternative branch, allowing a member with access to one application to attach its applicationId to a dokploy-server schedule and run a supplied script as root through schedule.runManually. This issue is fixed in version 0.29.13.
mitre CVSS3.1
9.9
Vulnerability type
CWE-269
Improper Privilege Management
CWE-863
Incorrect Authorization
- https://github.com/Dokploy/dokploy/security/advisories/GHSA-r89g-h7x9-phr2 x_refsource_CONFIRM
- https://github.com/Dokploy/dokploy/pull/4869 x_refsource_MISC
- https://github.com/Dokploy/dokploy/commit/1e3f10bd22c1c28a7b65a2d7ac15a0a5e47599... x_refsource_MISC
- https://github.com/Dokploy/dokploy/releases/tag/v0.29.13 x_refsource_MISC
Published: 10 Aug 2026 · Updated: 10 Aug 2026 · First seen: 10 Aug 2026