CVE-2026-72876: Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy/server/api/routers/swarm.ts accept another organization’s serverId without an activeOrganizationId ownership check, and getNodeInfo in packages/server/src/services/docker.ts interpolates nodeId into execAsyncRemote, allowing a caller with server:read permission to execute arbitrary commands as the configured SSH user on another tenant’s server. This issue is fixed in version 0.29.13.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dokployto a version that resolves this vulnerability.Fixed in 0.29.13
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72876?
CVE-2026-72876 has a critical severity score of 9.9.
How do I fix CVE-2026-72876?
To fix CVE-2026-72876, upgrade to Dokploy version 0.29.13 or later.
What are the potential impacts of CVE-2026-72876?
CVE-2026-72876 can lead to remote code execution (RCE) on another tenant's server due to improper access checks.
What type of vulnerability is CVE-2026-72876?
CVE-2026-72876 is classified as an OS Command Injection vulnerability.
In which versions of Dokploy is CVE-2026-72876 present?
CVE-2026-72876 is present in Dokploy versions prior to 0.29.13.