PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72902 Dokploy CVE debrief

CVE-2026-72902 Dokploy Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), has a critical command injection vulnerability prior to version 0.29.13. This vulnerability allows authenticated users to execute arbitrary commands on local or SSH-connected target servers due to improper interpolation of the password field in the registry.testRegistry and registry.testRegistryById functions. The issue is fixed in version 0.29.13. Administrators and users of Dokploy instances should assess exposure and prioritize upgrading to version 0.29.13 or later.

Vendor
Dokploy
Product
Unknown
CVSS
CRITICAL 9.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-09-08
Advisory published
2026-08-10
Advisory updated
2026-09-08

Who should care

Administrators and users of Dokploy instances should assess exposure and prioritize upgrading to version 0.29.13 or later. This includes reviewing and restricting authenticated user permissions, monitoring for suspicious activity, and verifying current version and exposure. Operators, platform administrators, and security teams should be aware of the potential impacts and take necessary actions to mitigate the vulnerability.

Why it matters

CVE-2026-72902 is a critical command injection vulnerability in Dokploy that allows authenticated users to execute arbitrary commands on local or SSH-connected target servers. Defenders should prioritize upgrading to version 0.29.13 or later and restrict authenticated user permissions.

  • Potential for authenticated users to execute arbitrary commands on local or SSH-connected target servers
  • Possible lateral movement and exploitation of connected systems
  • Need for verification of current version and exposure
  • Priority for upgrading to version 0.29.13 or later

Technical summary

The Dokploy platform has a command injection vulnerability prior to version 0.29.13. An authenticated user can execute arbitrary commands on a local or SSH-connected target server due to improper interpolation of the password field in the registry.testRegistry and registry.testRegistryById functions. This issue allows potential lateral movement and exploitation of connected systems. Defenders should prioritize upgrading to version 0.29.13 or later and restrict authenticated user permissions. The vulnerability has a CVSS score of 9.9 and is considered critical.

Defensive priority

High

Recommended defensive actions

  • Upgrade Dokploy to version 0.29.13 or later
  • Review and restrict authenticated user permissions
  • Monitor for suspicious activity on Dokploy instances
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. The Dokploy platform has a command injection vulnerability prior to version 0.29.13. The issue is fixed in version 0.29.13. Defenders should verify current version and exposure, and review and restrict authenticated user permissions. The CVE record was published on 2026-08-10T20:17:35.707Z and has not been modified since then.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72902 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72902

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72902 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72902

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.