CVE-2026-72872Disclosure

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation and cloneBitbucketRepository in packages/server/src/utils/providers/bitbucket.ts interpolates those values into git clone commands executed through execAsync or execAsyncRemote, allowing a member with service deployment permission to execute arbitrary operating system commands on the Dokploy host or target server. This issue is fixed in version 0.29.13.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-11: 2Patch / Workaround · 2026-08-11: 2Technical Details · 2026-08-11: 208-11
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-72872 - Critical RCE in Dokploy. Unvalidated input leads to OS command injection via git clone. CVSS 9.9. Unpatched. Update immediately if affected. #CVE #Dokploy #infosec https://www.valtersit.com/cve/CVE-2026-72872 #SysAdmin #cybersecurity #CVE #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #denmark #norway #japan #korea #china #unitedstates #usa

    Post summary

    The post announces CVE‑2026‑72872, details a critical RCE in Dokploy with a CVSS of 9.9, and urges users to update, but does not share a PoC, exploit, or evidence of active exploitation.

    0001067
    1.0K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-72872 - Critical RCE in Dokploy. Unvalidated input leads to OS command injection via git clone. CVSS 9.9. Unpatched. Update immediately if affected. https://www.valtersit.com/cve/CVE-2026-72872 #CVE #Dokploy #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta

    Post summary

    This post announces a critical remote code execution vulnerability in Dokploy caused by unvalidated input during git clone, highlights its high CVSS score, and urges immediate patching.

    0000059
    1.0K followersView on X

Explore more