Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-86059: Dokploy exposes Git credentials to unauthorized users

CVE-2026-86059 · published 17 days ago
Summary

In versions of Dokploy before 0.29.13, members of an organization could view plaintext Git provider credentials, such as OAuth tokens and private keys, through several API endpoints even if they did not have permission to use those providers. This allows them to access private repositories or change external workflows. Upgrade to version 0.29.13 or later to close the exposure.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
dokploy dokploy < 0.29.13
Original advisory text
Dokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and application.one
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials through github.one, gitlab.one, gitea.one, and bitbucket.one because those protected procedures return full provider rows without applying getAccessibleGitProviderIds or an organization check. The application.one route also returns nested GitHub, GitLab, Gitea, and Bitbucket relations from findApplicationById with GitHub App private keys, OAuth tokens, client secrets, webhook secrets, and app passwords even when hasGitProviderAccess is false. A member with application read access or a provider identifier can therefore bypass per-member provider assignment and use the exposed credentials to access private repositories or manipulate external workflows. This issue is fixed in version 0.29.13.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.6 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-200Information Exposure
CWE-862Missing Authorization
Timeline
Published22 Sep 2026
Updated9 Oct 2026
First seen22 Sep 2026
Sources
CVE-2026-86059 · MITRE
Track software like this
Free during beta