Impact
Dokploy's server.remove API mutation accepts a caller‑supplied serverId and then performs server deletion without checking that the caller’s organization matches the server’s organization. An authenticated owner or administrator from one organization who knows another organization’s serverId can delete that server’s registration and deployment records, interrupt management of the target organization, and obtain the plaintext SSH private key associated with the deleted server. The vulnerability permits unauthorized deletion and credential exposure within a PaaS environment, threatening both availability and confidentiality for affected accounts.
Affected Systems
The flaw exists in Dokploy versions 0.28.7 up to and including 0.29.13. Affected deployments are running the open‑source PaaS distributed under the Dokploy project. No other vendors or products are impacted.
Risk and Exploitability
The CVSS score is 8.4, indicating a high‑severity flaw. Exploitation requires an authenticated user with server:delete privileges in one organization and prior knowledge of an eligible serverId from another organization. The attack vector is remote, carried out over the authenticated API or UI. EPSS data is not available. The vulnerability is not listed in CISA KEV. The impact is significant because it can lead to loss of control over deployments, service interruption, and theft of credentials.
OpenCVE Enrichment