CVE-2026-72866: WebSocket Terminal Auth Bypass
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/server/wss/terminal.ts validates a session but does not authorize access to the requested server. An authenticated user can connect to /terminal?serverId=local, select the special serverId=local branch, and obtain an interactive terminal on the Dokploy host without an organization role or server-access check. This issue is fixed in version 0.29.13.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
dokployto a version that resolves this vulnerability.Fixed in 0.29.13
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72866?
The severity of CVE-2026-72866 is high with a score of 8.8.
How do I fix CVE-2026-72866?
To fix CVE-2026-72866, update Dokploy to version 0.29.13 or later.
What type of vulnerability is CVE-2026-72866?
CVE-2026-72866 is a WebSocket terminal authentication bypass vulnerability.
What are the potential impacts of CVE-2026-72866?
The potential impacts of CVE-2026-72866 include unauthorized access to sensitive server functionalities.
Who is affected by CVE-2026-72866?
Users of Dokploy versions prior to 0.29.13 are affected by CVE-2026-72866.