CRITICALVulnerability

CVE-2026-72863

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. They establish who the user is via validateRequest() and then proceed without consulting the role/permission model that every tRPC procedure enforces. Any authenticated member, can therefore open an interactive shell into any container on the host, including the dokploy container that mounts the Docker socket, and from there obtain root on the host, escaping the application and crossing every tenant boundary. This vulnerability is fixed in 0.29.13.

Properties

severity
CRITICAL
score
9.9
epss_score
0.00298
cve_id
CVE-2026-72863
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
published_at
2026-08-10T19:17:34.870
last_modified
2026-09-08T20:54:37.790
epss_percentile
0.22132

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (3)

[Weakness]Authorization Bypass Through User-Controlled Key
[Weakness]Improper Privilege Management
[Weakness]Missing Authorization

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72863 — Ninja Signal Threat Intelligence | Ninja Signal