CVE-2026-54636Patch(dokku / dokku)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dokku dokku systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the Docker container and execute commands on the host as the Dokku user. This vulnerability is fixed in 0.38.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dokku

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
dokku

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-26: 2Mentions · 2026-06-28: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-06-28: 1Technical Details · 2026-06-26: 2Technical Details · 2026-06-28: 106-2606-28
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-262
Disclosure1Patch1
2026-06-281
Patch1
Full discourse3 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-54636 — CVSS 9/10 █████████░ Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/weIesaB5cC

    Post summary

    The tweet announces a critical CVE in Dokku’s cron plugin and urges users to patch to version 0.38.7, with no PoC or exploitation details provided.

    10011226
    62 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-54636 - Critical OS Command Injection in #Dokku. #App.json cron commands with shell chars can break container isolation. #CVSS 9.0. Update to 0.38.7. @dokku #infosec #cybersecurity #devsecops #devops #developers #git #github #gitlab More: https://www.valtersit.com/cve/CVE-2026-54636

    Post summary

    CVE‑2026‑54636 is a critical OS command injection in Dokku (CVSS 9.0) that breaks container isolation, with a fix released in version 0.38.7.

    0001082
    965 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-54636 Command Injection in Dokku Cron Plugin Versions Before 0.38.7 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-54636

    Post summary

    CVE-2026-54636 is a reported command injection vulnerability in Dokku Cron Plugin versions prior to 0.38.7, with basic disclosure details but no PoC, exploit, patch, or evidence of active exploitation.

    00010132
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdokkudokku---

Explore more