PatchSiren cyber security CVE debrief
CVE-2026-72865 Dokploy CVE debrief
CVE-2026-72865 Dokploy Remote Code Execution Vulnerability. Dokploy is a free, self-hostable Platform as a Service (PaaS) with a critical vulnerability allowing authenticated members with compose write and deploy permissions to execute arbitrary operating-system commands. The vulnerability is fixed in version 0.29.13. Administrators and users of Dokploy instances should assess exposure and apply the patch to prevent exploitation. Restricting compose write and deploy permissions to trusted users can also help mitigate the vulnerability.
- Vendor
- Dokploy
- Product
- Unknown
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-09-08
Who should care
Administrators and users of Dokploy instances should assess exposure and apply the patch to prevent exploitation. Restricting compose write and deploy permissions to trusted users can also help mitigate the vulnerability.
Why it matters
CVE-2026-72865 is a critical vulnerability in Dokploy that allows authenticated members with compose write and deploy permissions to execute arbitrary operating-system commands. The vulnerability is fixed in version 0.29.13, and administrators should assess exposure and apply the patch promptly.
- Potential for arbitrary operating-system command execution in the Docker-privileged Dokploy host context.
- Possible lateral movement and exploitation by authenticated members with compose write and deploy permissions.
- Need for prompt patching to version 0.29.13 to prevent exploitation.
- Verification of compose write and deploy permissions and restriction to trusted users.
Technical summary
CVE-2026-72865 is a critical vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS). Prior to version 0.29.13, an authenticated member with compose write and deploy permissions can supply a crafted composePath and execute arbitrary operating-system commands in the Docker-privileged Dokploy host context. The vulnerability is fixed in version 0.29.13, and administrators should assess exposure and apply the patch promptly. The vulnerability allows for potential lateral movement and exploitation by authenticated members with compose write and deploy permissions.
Defensive priority
High
Recommended defensive actions
- Review and apply the patch (version 0.29.13) to prevent exploitation.
- Restrict compose write and deploy permissions to trusted users.
- Monitor Dokploy instances for suspicious activity.
- Verify compose write and deploy permissions are restricted to trusted users.
- Review system logs for suspicious Docker activity.
- Perform regular security audits to detect potential vulnerabilities.
- Implement additional security measures to prevent lateral movement.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. The Dokploy team has released a fixed version (0.29.13) and provided additional information through GitHub. The vulnerability allows authenticated members with compose write and deploy permissions to supply a crafted composePath and execute arbitrary operating-system commands in the Docker-privileged Dokploy host context. Evidence is limited to CVE and NVD details; defenders should verify compose write and deploy permissions and review system logs for suspicious Docker
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72865 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72865
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72865 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72865
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Dokploy/dokploy/commit/d48037a80203bb0ecaec4f5653aef75fcfdb656d
-
Source reference
Unverified legacy reference
URL: https://github.com/Dokploy/dokploy/pull/4863
-
Source reference
Unverified legacy reference
URL: https://github.com/Dokploy/dokploy/releases/tag/v0.29.13
-
Source reference
Unverified legacy reference
URL: https://github.com/Dokploy/dokploy/security/advisories/GHSA-8r5w-vqjr-8c44
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.