CVE-2026-72734

high

Description

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in apps/dokploy/server/api/routers/server.ts accepts a caller-controlled serverId and calls haveActiveServices, findServerById, removeDeploymentsByServerId, and deleteServer without verifying that currentServer.organizationId equals ctx.session.activeOrganizationId. An authenticated owner or administrator with server:delete in one organization who previously observed another organization's serverId can delete that organization's server registration and deployment records, interrupt Dokploy management, and receive the associated plaintext SSH private key even though server.one denies the same cross-organization read. This issue is fixed in version 0.29.13.

References

https://github.com/Dokploy/dokploy/security/advisories/GHSA-3rpx-c3j9-q99x

https://github.com/Dokploy/dokploy/releases/tag/v0.29.13

https://github.com/Dokploy/dokploy/pull/4874

https://github.com/Dokploy/dokploy/commit/4aee66b2d1dc2c027749a541e553aa49947075c1

Details

Source: Mitre, NVD

Published: 2026-08-10

Updated: 2026-08-11

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:P

Severity: Medium

CVSS v3

Base Score: 8.4

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

Severity: High

EPSS

EPSS: 0.00297