CRITICALVulnerability

CVE-2026-72868

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provider, and bucket fields from destination.testConnection into an rclone ls command executed through child_process.exec. The `withPermission("destination", "create")` path permits a low-privileged organization member to reach the mutation, close a quoted argument with a crafted field, and execute arbitrary commands in the root Dokploy container, which has access to the host Docker socket. This issue is fixed in version 0.29.13.

Properties

severity
CRITICAL
score
9.9
epss_score
0.00363
cve_id
CVE-2026-72868
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
published_at
2026-08-10T19:17:35.600
last_modified
2026-09-08T20:54:37.790
epss_percentile
0.29399

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (2)

[Weakness]Missing Authorization
[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72868 — Ninja Signal Threat Intelligence | Ninja Signal