No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 11 Aug 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dokploy
Dokploy dokploy |
|
| Vendors & Products |
Dokploy
Dokploy dokploy |
Tue, 11 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in apps/dokploy/server/api/routers/server.ts accepts a caller-controlled serverId and calls haveActiveServices, findServerById, removeDeploymentsByServerId, and deleteServer without verifying that currentServer.organizationId equals ctx.session.activeOrganizationId. An authenticated owner or administrator with server:delete in one organization who previously observed another organization's serverId can delete that organization's server registration and deployment records, interrupt Dokploy management, and receive the associated plaintext SSH private key even though server.one denies the same cross-organization read. This issue is fixed in version 0.29.13. | |
| Title | Dokploy: Cross-organization authorization bypass in server.remove allows deletion of another organization's server registration | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-11T02:00:39.079Z
Reserved: 2026-08-10T13:48:09.546Z
Link: CVE-2026-72734
Updated: 2026-08-11T02:00:34.504Z
Status : Received
Published: 2026-08-10T18:18:51.823
Modified: 2026-08-11T03:18:01.790
Link: CVE-2026-72734
No data.
OpenCVE Enrichment
Updated: 2026-08-11T03:45:03Z