What is CVE-2026-72875?
CVE-2026-72875 is a vulnerability in Dokploy, a self-hostable PaaS, affecting versions before 0.29.13. The flaw lies in `settings.readTraefikFile` which improperly validates the path when reading Traefik configuration, potentially allowing remote code execution. Users should upgrade to the latest version immediately.
Azərbaycanca: CVE-2026-72875 Dokploy-un 0.29.13-dən əvvəlki versiyalarını təsir edən bir zəiflikdir. Tətbiq daxilində `settings.readTraefikFile` funksiyası traefik konfiqurasiya fayllarını oxuyarkən yetərsiz yoxlama səbəbindən təhlükəsizlik boşluğu yaradır. Bu, uzaqdan kod icrasına yol aça bilər, ona görə də istifadəçilər dərhal son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which Dokploy function was CVE-2026-72875 discovered?
The flaw is located in the `settings.readTraefikFile` function, which performs improper validation when reading Traefik configuration files.
How can users protect themselves from CVE-2026-72875?
Users should immediately upgrade to Dokploy version 0.29.13 or later, as versions before 0.29.13 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.