PatchSiren cyber security CVE debrief
CVE-2026-72902 Dokploy CVE debrief
CVE-2026-72902 Dokploy Command Injection Vulnerability. Dokploy, a free, self-hostable Platform as a Service (PaaS), has a critical command injection vulnerability prior to version 0.29.13. This vulnerability allows authenticated users to execute arbitrary commands on local or SSH-connected target servers due to improper interpolation of the password field in the registry.testRegistry and registry.testRegistryById functions. The issue is fixed in version 0.29.13. Administrators and users of Dokploy instances should assess exposure and prioritize upgrading to version 0.29.13 or later.
- Vendor
- Dokploy
- Product
- Unknown
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-09-08
Who should care
Administrators and users of Dokploy instances should assess exposure and prioritize upgrading to version 0.29.13 or later. This includes reviewing and restricting authenticated user permissions, monitoring for suspicious activity, and verifying current version and exposure. Operators, platform administrators, and security teams should be aware of the potential impacts and take necessary actions to mitigate the vulnerability.
Why it matters
CVE-2026-72902 is a critical command injection vulnerability in Dokploy that allows authenticated users to execute arbitrary commands on local or SSH-connected target servers. Defenders should prioritize upgrading to version 0.29.13 or later and restrict authenticated user permissions.
- Potential for authenticated users to execute arbitrary commands on local or SSH-connected target servers
- Possible lateral movement and exploitation of connected systems
- Need for verification of current version and exposure
- Priority for upgrading to version 0.29.13 or later
Technical summary
The Dokploy platform has a command injection vulnerability prior to version 0.29.13. An authenticated user can execute arbitrary commands on a local or SSH-connected target server due to improper interpolation of the password field in the registry.testRegistry and registry.testRegistryById functions. This issue allows potential lateral movement and exploitation of connected systems. Defenders should prioritize upgrading to version 0.29.13 or later and restrict authenticated user permissions. The vulnerability has a CVSS score of 9.9 and is considered critical.
Defensive priority
High
Recommended defensive actions
- Upgrade Dokploy to version 0.29.13 or later
- Review and restrict authenticated user permissions
- Monitor for suspicious activity on Dokploy instances
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. The Dokploy platform has a command injection vulnerability prior to version 0.29.13. The issue is fixed in version 0.29.13. Defenders should verify current version and exposure, and review and restrict authenticated user permissions. The CVE record was published on 2026-08-10T20:17:35.707Z and has not been modified since then.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72902 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72902
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72902 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72902
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Dokploy/dokploy/commit/d3f522b7a6f5100fc0fc0bff5851e48d11d459e2
-
Source reference
Unverified legacy reference
URL: https://github.com/Dokploy/dokploy/pull/4875
-
Source reference
Unverified legacy reference
URL: https://github.com/Dokploy/dokploy/releases/tag/v0.29.13
-
Source reference
Unverified legacy reference
URL: https://github.com/Dokploy/dokploy/security/advisories/GHSA-w6r4-f26v-8g36
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.