Description
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belonging to other organizations if they know the scheduleId/serverId. Schedule types server and dokploy-server write and execute scripts on the host or remote servers, enabling RCE on the Dokploy host or a target server.
Published: 2026-05-29
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Dokploy PaaS application (versions 0.26.7 and earlier) contains a flaw in the schedule router where organization and role checks are omitted. This allows any authenticated user who can guess or obtain a scheduleId or serverId to create, update, execute, or delete schedules that belong to other organizations. When a schedule of type server or dokploy-server is run, the application writes a script to the host or a target server and executes it, providing an attacker with remote command execution on the Dokploy host or the remote server.

Affected Systems

Affected by this vulnerability are installations of Dokploy, the free, self‑hostable Platform as a Service, that are running version 0.26.7 or earlier. No later releases are mentioned as fixing the issue.

Risk and Exploitability

The CVSS score of 9.9 classifies this as critical, and because the flaw requires only authentication, it can be exercised by any user with valid credentials. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no currently known widespread exploitation. However, given the simple authentication requirement and the potential to run arbitrary scripts on the host or any target server, the risk to confidentiality, integrity, and availability is high. Attackers can gain full control of the affected machine by following the described path of creating a malicious schedule, provided that organization and role checks are not enforced.

Generated by OpenCVE AI on May 29, 2026 at 18:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dokploy to a version newer than 0.26.7 where the schedule router includes proper organization and role checks.
  • If an upgrade is not immediately possible, restrict the ability to create and manage schedules to users with the necessary ownership or delete all schedules that belong to other organizations.
  • Disable the server/dokploy‑server schedule types until the issue is patched, or isolate these schedules on a dedicated environment with limited permissions.
  • Conduct a review of role‑based access controls and audit scheduled scripts for unauthorized commands.

Generated by OpenCVE AI on May 29, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Dokploy
Dokploy dokploy
Vendors & Products Dokploy
Dokploy dokploy

Fri, 29 May 2026 17:30:00 +0000

Type Values Removed Values Added
Description Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belonging to other organizations if they know the scheduleId/serverId. Schedule types server and dokploy-server write and execute scripts on the host or remote servers, enabling RCE on the Dokploy host or a target server.
Title Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution
Weaknesses CWE-269
CWE-78
CWE-862
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-05-29T16:11:19.414Z

Reserved: 2026-05-12T20:31:43.450Z

Link: CVE-2026-45632

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-05-29T18:17:11.373

Modified: 2026-05-29T20:25:00.760

Link: CVE-2026-45632

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T19:00:06Z

Weaknesses