


Perceptive Security
SOC/SIEM Consultancy

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-containe…
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 21:09:42
Source:
nvd.nist.gov
Cloud & Virtualization, Web Technologies
Dokploy, a free self-hostable Platform as a Service (PaaS), contains a critical command injection vulnerability in versions 0.26.6 and earlier. The vulnerability exists in the /docker-container-logs WebSocket endpoint where the tail and since parameters are not properly validated. These parameters are directly concatenated into shell commands, allowing authenticated users to execute arbitrary commands with root privileges. This represents a severe security flaw that could lead to complete system compromise.
Technical details
Mitigation steps:
Affected products:
Dokploy
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45633
https://github.com/Dokploy/dokploy/security/advisories/GHSA-wmqj-wr9q-327p
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
