CVE-2026-72868 | Dokploy up to 0.29.12 Destination Router destination.ts child_process.exec privileges management
A vulnerability marked as very critical has been reported in Dokploy up to 0.29.12. This issue affects the function child_process.exec of the file apps/dokploy/server/api/routers/destination.ts of the component Destination Router. This manipulation of the argument accessKey/secretAccessKey/region/endpoint/provider/bucket causes improper privilege management.
This vulnerability appears as CVE-2026-72868. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More