CRAC Learning - Tech@cracbotDisclosure
The post announces the discovery and ongoing analysis of CVE-2026-24841, a critical command injection flaw in Dokploy prior to version 0.26.6, citing its high CVSS score and linking to the NVD entry.
PulsePatch.io@pulsepatchioPatch
CVE‑2026‑24841 is an authenticated remote code execution vulnerability in Dokploy caused by command injection in the Docker terminal; users are urged to update the software to mitigate the risk.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces a command injection vulnerability in Dokploy’s WebSocket endpoint affecting versions prior to 0.26.6.
CVEFind.com@CveFindComDisclosure
The post alerts to a critical command injection flaw in Dokploy versions prior to 0.26.6 that permits authenticated attackers to run arbitrary commands through a WebSocket endpoint, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.
CVE@CVEnewDisclosure
Dokploy’s WebSocket interface contains a critical command injection flaw in versions earlier than 0.26.6; no PoC, exploit, patch, or active exploitation details are provided.
0day Signal@0dayPublishingDisclosure
The tweet announces CVE‑2026‑24841 as a trivial command injection in Dokploy’s WebSocket endpoint that allows authenticated users host‑level access; no PoC, exploit, or patch is referenced.