CVE-2026-24840: Dokploy uses hardcoded credentials in installation script, which could result in database access

Published Jan 28, 2026
·
Updated

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located at https://dokploy.com/install.sh, line 154) uses a hardcoded password when creating the database container. This means that nearly all Dokploy installations use the same database credentials and could be compromised. Version 0.26.6 contains a patch for the issue.

Affected Software

2 affected components
dokploy/dokploy<0.26.6
Dokploy Dokploy<0.26.6

Event History

Jan 28, 2026
CVE Published
via MITRE·12:15 AM
Data Sourced
via MITRE·12:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 27, 58104
Event
via FIRST·01:20 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-24840?

CVE-2026-24840 is a critical vulnerability due to hardcoded credentials that can lead to unauthorized database access.

2

How do I fix CVE-2026-24840?

To fix CVE-2026-24840, upgrade to Dokploy version 0.26.6 or later where the hardcoded credentials are removed.

3

What versions of Dokploy are affected by CVE-2026-24840?

CVE-2026-24840 affects all Dokploy versions prior to 0.26.6.

4

What risks are associated with CVE-2026-24840?

The risks associated with CVE-2026-24840 include potential unauthorized access to the database and compromise of sensitive data.

5

Where can I find more details about CVE-2026-24840?

More details about CVE-2026-24840 can be found in the advisory posted on the official Dokploy GitHub repository.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203