
Dokploy before 0.29.13 has a 9.9 control-plane flaw: a low-privilege member could reach container terminals and potentially host root. Upgrade, review terminal/Docker activity, and rotate deployment secrets if access cannot be ruled out. https://nvd.nist.gov/vuln/detail/CVE-2026-72863
Post summary
CVE-2026-72863 is a high‑severity control‑plane vulnerability in Dokploy that lets low‑privileged users reach container terminals and potentially gain root; the advisory recommends upgrading, reviewing activity, and rotating secrets.
