Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-72902: Dokploy: Authenticated User Can Execute Commands on Server

CVE-2026-72902 CVE-2026-72902
Summary

Dokploy, a self-hosted Platform as a Service, had a security issue that allowed an authenticated user to execute commands on a server. This means an attacker could gain access to sensitive information or take control of the server. To fix this, update to version 0.29.13 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
dokploy dokploy < 0.29.13
Original title
Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById
Original description
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands on a local or SSH-connected target server because registry.testRegistry and registry.testRegistryById in apps/dokploy/server/api/routers/registry.ts interpolate the password field into an execAsyncRemote shell command instead of using safeDockerLoginCommand. This issue is fixed in version 0.29.13.
nvd CVSS3.1 9.9
Vulnerability type
CWE-78 OS Command Injection
Published: 10 Aug 2026 · Updated: 10 Aug 2026 · First seen: 10 Aug 2026