What is CVE-2026-72865?
CVE-2026-72865 was found in the self-hostable Dokploy PaaS. Before version 0.29.13, the 'compose.update' operation uses an unvalidated 'composePath' that is interpolated into 'docker compose' commands, potentially allowing remote code execution. Users should immediately update to version 0.29.13 or later.
Azərbaycanca: CVE-2026-72865 öz-özünə host edilə bilən Dokploy PaaS platformasında aşkarlanıb. 0.29.13 versiyasından əvvəl 'compose.update' əməliyyatı doğrulanmamış 'composePath' məlumatını 'docker compose' əmrlərinə əlavə edir, bu da uzaqdan kod icrasına səbəb ola bilər. İstifadəçilər dərhal 0.29.13 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
In which platform was CVE-2026-72865 discovered?
CVE-2026-72865 was found in the self-hostable Dokploy PaaS.
What should users do to protect against this vulnerability?
Users should immediately update to version 0.29.13 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.