What is CVE-2026-72866?
CVE-2026-72866 is an authorization bypass vulnerability in the Dokploy PaaS WebSocket terminal handler. Prior to version 0.29.13, any authenticated user could connect to the `/terminal?serverId=local` endpoint to gain unauthorized access to a server. Upgrading to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-72866 Dokploy platformasında WebSocket terminallar üçün avtorizasiya zəifliyidir. 0.29.13 versiyasından əvvəl autentifikasiya olunmuş istənilən istifadəçi xüsusi server ID-si ilə `/terminal` endpointinə qoşularaq icazəsiz serverə giriş əldə edə bilər. Zəiflikdən qorunmaq üçün dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Dokploy
FAQ2
Does exploiting CVE-2026-72866 require the attacker to be authenticated?
Yes, any authenticated user could connect to the `/terminal?serverId=local` endpoint to gain unauthorized access to a server.
Which versions of Dokploy are affected by CVE-2026-72866 and how to mitigate it?
The vulnerability affects versions prior to 0.29.13. Upgrading to the latest version is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.