What is CVE-2026-72869?
CVE-2026-72869 exists in the Dokploy self-hostable PaaS platform. Versions prior to 0.29.13 are vulnerable because the "backup.restoreBackupWithLogs" tRPC subscription unsafely embeds the "databaseName" parameter into restore commands for PostgreSQL, MariaDB, MySQL, and MongoDB, leading to a potential command injection. Users should immediately upgrade to version 0.29.13 or later.
Azərbaycanca: CVE-2026-72869 Dokploy platformasında aşkar edilmişdir. 0.29.13 versiyasından əvvəlki versiyalarda "backup.restoreBackupWithLogs" tRPC funksiyası "databaseName" parametrini təhlükəsiz şəkildə idarə etmədiyi üçün PostgreSQL, MariaDB, MySQL və MongoDB komandalarında potensial command injection zəifliyi yaranır. İstifadəçilər dərhal 0.29.13 və ya daha yuxarı versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which versions of Dokploy are affected by CVE-2026-72869?
This vulnerability exists in all versions of the Dokploy platform prior to 0.29.13.
How can I protect against CVE-2026-72869?
Users should immediately upgrade Dokploy to version 0.29.13 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.