CVE-2026-24840Disclosure(dokploy / dokploy)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dokploy dokploy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located at https://dokploy.com/install.sh, line 154) uses a hardcoded password when creating the database container. This means that nearly all Dokploy installations use the same database credentials and could be compromised. Version 0.26.6 contains a patch for the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dokploy

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
dokploy

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-28: 2Mentions · 2026-02-02: 1Patch / Workaround · 2026-01-28: 1Technical Details · 2026-01-28: 2Technical Details · 2026-02-02: 101-2802-02
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-282
Disclosure1General1
2026-02-021
Disclosure1
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-24840 (CVSS:8.0, HIGH) is Undergoing Analysis. Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in th..https://nvd.nist.gov/vuln/detail/CVE-2026-24840 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-24840, a high‑severity vulnerability in Dokploy caused by a hardcoded credential, and indicates the issue is currently under analysis.

    0000043
    171 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24840 Hardcoded Database Credentials Vulnerability in Dokploy Platform Before 0.26.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24840

    Post summary

    The message announces CVE-2026-24840, a hardcoded database credentials flaw in Dokploy Platform, and indicates that version 0.26.6 addresses the issue.

    0000062
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24840 Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located at htt… https://www.cve.org/CVERecord?id=CVE-2026-24840

    Post summary

    The post references CVE-2026-24840 in Dokploy, pointing out a hardcoded credential in installation scripts before version 0.26.6, but provides no evidence of exploitation or mitigation.

    00000245
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdokploydokploy---

Explore more