Impact
Dokploy is a self-hosted Platform as a Service that allows the scheduling of scripts to run on the host. Between versions 0.29.2 and 0.29.12, the API functions for creating or updating schedules derived the target service ID from the supplied application or compose ID but applied the owner/admin gate only in an alternative branch. This oversight allowed a non‑admin member with application access to attach an arbitrary application ID to a schedule, trigger that schedule, and run a supplied script with root privileges on the underlying host.
Affected Systems
The vulnerability affects the Dokploy platform in all releases from version 0.29.2 through 0.29.12 inclusive. Versions 0.29.13 and later contain the fix that restores the owner/admin check for server‑level schedules.
Risk and Exploitability
The CVSS score of 9.9 signals a critical risk, indicating full compromise of the host’s confidentiality, integrity, and availability if exploited. EPSS information is not available, and the vulnerability is not currently listed in the CISA KEV catalog, suggesting limited known exploitation to date. The likely attack vector is remote: any user with a non‑admin appointment who can submit a schedule creation or update request through the Dokploy API or web interface can chain the flaw to obtain root access on the host. This path requires only legitimate credentials and the ability to attach an application ID to a schedule, making it a straightforward privilege escalation opportunity for internal actors.
OpenCVE Enrichment