CVE-2026-72866 | Dokploy up to 0.29.12 WebSocket handler terminal.ts serverId improper authorization
A vulnerability was found in Dokploy up to 0.29.12. It has been declared as critical. This affects an unknown part of the file apps/dokploy/server/wss/terminal.ts of the component WebSocket handler. Executing a manipulation of the argument serverId can lead to improper authorization.
This vulnerability is tracked as CVE-2026-72866. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More