What is CVE-2026-72876?
CVE-2026-72876 affects Dokploy, a self-hostable PaaS. An authenticated user can access node information from other organizations via endpoints like `swarm.getNodes` due to a missing ownership check on the `serverId` parameter. Upgrading to version 0.29.13 is recommended.
Azərbaycanca: CVE-2026-72876 Dokploy öz-özünə host edilən PaaS-da aşkarlanıb. swarm.ts-də serverId parametri üzərində mülkiyyət yoxlamasının olmaması səbəbindən autentifikasiya olunmuş istifadəçi başqa təşkilata məxsus node məlumatlarını (`swarm.getNodes`, `swarm.getNodeInfo` kimi) oxuya bilir. 0.29.13 versiyasına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What issue does CVE-2026-72876 cause in the Dokploy platform?
This vulnerability allows an authenticated user to read node information belonging to other organizations via endpoints like `swarm.getNodes` due to a missing ownership check on the `serverId` parameter in `swarm.ts`.
What should be done to protect against CVE-2026-72876?
It is recommended to upgrade Dokploy to version 0.29.13.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.