What is CVE-2026-72863?
CVE-2026-72863 is a vulnerability in Dokploy where WebSocket handlers for terminals and log streamers authenticate users but fail to perform authorization checks. This allows any authenticated user to access these features without role or permission validation. Updating to version 0.29.13 or later is required to mitigate the issue.
Azərbaycanca: CVE-2026-72863 zəifliyi Dokploy platformasında aşkarlanıb, burada WebSocket handler-lər autentifikasiyanı təmin etsə də, avtorizasiya yoxlanışı aparmır. Bu, autentifikasiya olunmuş istənilən istifadəçiyə rollerə əsaslanan icazə məhdudiyyəti olmadan terminal və log axınlarına giriş əldə etməyə imkan verir. Təsirə məruz qalmamaq üçün 0.29.13 versiyasına qədər yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What functionalities in Dokploy are affected by CVE-2026-72863?
This vulnerability affects the WebSocket handlers for terminals and log streamers.
What version should be upgraded to in order to mitigate CVE-2026-72863?
You need to upgrade Dokploy to version 0.29.13 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.