


Perceptive Security
SOC/SIEM Consultancy

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result…
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 21:09:42
Source:
nvd.nist.gov
Cloud & Virtualization, Identity & Access
Dokploy, a self-hostable Platform as a Service, contains a critical vulnerability in versions 0.26.7 and earlier where the schedule router fails to enforce organization/role checks. This allows any authenticated user to manipulate schedules belonging to other organizations if they know the scheduleId/serverId. The vulnerability enables remote code execution on the Dokploy host or target servers through schedule types that write and execute scripts. The flaw represents a significant authorization bypass that can lead to complete system compromise.
Technical details
Mitigation steps:
Affected products:
Dokploy
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45632
https://github.com/Dokploy/dokploy/security/advisories/GHSA-7wmr-57mg-h5q6
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
