PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72867 Dokploy CVE debrief

CVE-2026-72867 Dokploy Arbitrary Host Command Execution. Dokploy, a free, self-hostable Platform as a Service (PaaS), contains a critical vulnerability allowing low-privileged authenticated users to execute arbitrary host commands. This issue arises from an incomplete fix for CVE-2026-45628, enabling malicious custom Git branch storage. When a deployment is triggered, the stored branch is passed to shell-based Git clone commands, resulting in command execution. System administrators and security teams managing Dokploy deployments should assess their exposure and prioritize remediation to prevent potential exploitation and lateral movement within the PaaS environment.

Vendor
Dokploy
Product
Unknown
CVSS
CRITICAL 9.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-09-08
Advisory published
2026-08-10
Advisory updated
2026-09-08

Who should care

System administrators and security teams responsible for Dokploy deployments should assess their exposure and prioritize remediation. This vulnerability requires attention from roles managing PaaS environments, especially those with low-privileged authenticated users.

Why it matters

CVE-2026-72867 is a critical vulnerability in Dokploy that allows low-privileged authenticated users to execute arbitrary host commands. System administrators and security teams managing Dokploy deployments should assess their exposure and prioritize remediation to prevent potential exploitation and lateral movement within the PaaS environment.

  • Potential for arbitrary host command execution by low-privileged authenticated users
  • Risk of lateral movement and exploitation within the PaaS environment
  • Need for verification of Dokploy version and exposure to vulnerable configurations
  • Priority for updating to version 0.29.13 or later to mitigate the vulnerability

Technical summary

CVE-2026-72867 is a critical vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS). The issue arises from an incomplete fix for CVE-2026-45628, allowing a low-privileged authenticated user to store a malicious custom Git branch. When the user triggers a deployment, the stored branch is passed to shell-based Git clone commands, resulting in arbitrary host command execution. The vulnerability is fixed in version 0.29.13. Dokploy deployments should be reviewed and updated to prevent potential exploitation. The CVE record and NVD entry provide details on the vulnerability, including affected versions and fixed releases.

Defensive priority

High

Recommended defensive actions

  • Review and update Dokploy to version 0.29.13 or later
  • Restrict access to authenticated users with low privileges
  • Monitor for suspicious activity related to Git branch updates and deployments
  • Perform regular security audits and vulnerability assessments
  • Implement additional logging and monitoring for Git-related activities
  • Verify Dokploy version and exposure to vulnerable configurations
  • Track and manage changes to Dokploy deployments and configurations

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in Dokploy, a free, self-hostable Platform as a Service (PaaS). The issue arises from an incomplete fix for CVE-2026-45628, allowing a low-privileged authenticated user to execute arbitrary host commands via a malicious custom Git branch.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72867 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72867

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72867 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72867

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.