CVE-2026-27130Disclosure

LOWCVSS 9.9 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this problem: inadequate input sanitization, lack of schema validation and direct shell interpolation. User-controlled application names are passed through inadequate sanitization (cleanAppName function only replaces spaces and converts to lowercase) before being interpolated directly into shell commands executed via execAsync() and execAsyncRemote(). An authenticated attacker can inject shell metacharacters (e.g., ;, $(), backticks, |, &) in the appName field during application creation, which are then executed with server-level privileges when service operations (start, stop, remove, scale) are triggered. This issue has been resolved in version 0.26.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-19: 4Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-19: 405-19
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets5 URLs
Full discourse4 posts
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-27130 (CVSS 9.9): Dokploy versions 0.26.6 and below contain OS command injection via the appName parameter. If your environment uses this self-hosted PaaS, update immediately. Details: https://nvd.nist.gov/vuln/detail/CVE-2026-27130 Need help reviewing exposure or updating your incident response plan? http://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning

    Post summary

    The post announces that Dokploy 0.26.6 and earlier versions are vulnerable to OS command injection (CVE-2026-27130) and urges users to update immediately to mitigate the high‑severity flaw.

    0000053
    80 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27130 Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cau… https://www.cve.org/CVERecord?id=CVE-2026-27130 ----- Traducción: CVE-2026-27130 Dok… http://infoflow.cloud`

    Post summary

    The note announces CVE-2026-27130 as an OS command injection in Dokploy 0.26.6 and earlier, providing basic vulnerability details but no PoC, exploit, active exploitation, or patch information.

    0000037
    78 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27130 Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cau… https://www.cve.org/CVERecord?id=CVE-2026-27130

    Post summary

    The post discloses that Dokploy versions 0.26.6 and earlier are vulnerable to OS command injection through the appName parameter, detailing the specific flaw that led to CVE‑2026‑27130.

    00000195
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27130 OS Command Injection in Dokploy 0.26.6 via Inadequate AppName Sanitization https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27130

    Post summary

    The text announces an OS command injection vulnerability in Dokploy 0.26.6 caused by insufficient AppName sanitization. No exploit, active usage, patch, or workaround details are included.

    0000067
    4.0K followersView on X

Explore more