PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72733 Dokploy CVE debrief

CVE-2026-72733 Dokploy Remote Command Injection. Dokploy, a free, self-hostable Platform as a Service (PaaS), has a critical remote command injection vulnerability prior to version 0.29.13. An authenticated member with backup-restore permission can inject operating-system commands that execute in the Dokploy host context through execAsync or execAsyncRemote, potentially leading to remote code execution, privilege escalation, and lateral movement. This issue is fixed in version 0.29.13.

Vendor
Dokploy
Product
Unknown
CVSS
CRITICAL 9.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-09-08
Advisory published
2026-08-10
Advisory updated
2026-09-08

Who should care

Administrators and users of Dokploy platform with backup-restore permissions should assess exposure and apply the patch. Dokploy administrators and users with backup-restore permissions should review and apply the patch in version 0.29.13, restrict backup-restore permissions to trusted users, and monitor for suspicious activity on Dokploy hosts.

Why it matters

CVE-2026-72733 is a critical remote command injection vulnerability in the Dokploy platform. An authenticated user with backup-restore permissions can inject operating-system commands, potentially leading to remote code execution, privilege escalation, and lateral movement. Dokploy administrators and users with backup-restore permissions should assess exposure and apply the patch in version 0.29.13.

  • Potential remote code execution on Dokploy hosts
  • Elevation of privileges for authenticated users with backup-restore permissions
  • Possible lateral movement within the host context

Technical summary

The Dokploy platform has a remote command injection vulnerability prior to version 0.29.13. An authenticated member with backup-restore permission can inject operating-system commands that execute in the Dokploy host context through execAsync or execAsyncRemote. This vulnerability can lead to potential remote code execution on Dokploy hosts, elevation of privileges for authenticated users with backup-restore permissions, and possible lateral movement within the host context. The issue is addressed in version 0.29.13.

Defensive priority

High

Recommended defensive actions

  • Review and apply the patch in version 0.29.13
  • Restrict backup-restore permissions to trusted users
  • Monitor for suspicious activity on Dokploy hosts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. The Dokploy platform has a remote command injection vulnerability prior to version 0.29.13. An authenticated member with backup-restore permission can inject operating-system commands that execute in the Dokploy host context through execAsync or execAsyncRemote. The vulnerability allows for potential remote code execution on Dokploy hosts, elevation of privileges for authenticated users with backup-restore permissions, and possible lateral movement within the host.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72733 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72733

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72733 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72733

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.