CVE-2026-45631: Dokploy: Pre-Auth Admin Takeover via Hardcoded Authentication Secret
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTERAUTHSECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge email verification JWTs, trigger auto-sign-in as admin, and execute commands on the host via the built-in SSH terminal. This vulnerability is fixed in 0.29.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
dokployto a version that resolves this vulnerability.Fixed in 0.29.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45631?
The severity of CVE-2026-45631 is critical, with a score of 10.
What does CVE-2026-45631 affect?
CVE-2026-45631 affects Dokploy versions 0.27.0 to before 0.29.3.
How do I fix CVE-2026-45631?
To fix CVE-2026-45631, upgrade Dokploy to version 0.29.3 or later.
What type of vulnerability is CVE-2026-45631?
CVE-2026-45631 is a pre-authentication admin takeover vulnerability due to a hardcoded authentication secret.
What can an attacker do with CVE-2026-45631?
An attacker can forge email verification JWTs, take over admin access, and execute commands on the host.