CVE-2026-72872 | Dokploy up to 0.29.12 Bitbucket Provider bitbucket.ts application.saveBitbucketProvider bitbucketOwner/bitbucketRepository privileges management
A vulnerability classified as critical has been found in Dokploy up to 0.29.12. The affected element is the function application.saveBitbucketProvider of the file packages/server/src/utils/providers/bitbucket.ts of the component Bitbucket Provider. Performing a manipulation of the argument bitbucketOwner/bitbucketRepository results in improper privilege management.
This vulnerability is known as CVE-2026-72872. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More