CVE-2026-72878Patch

LOWCVSS 9.6 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline constructs shell commands by directly interpolating user-controlled database fields into bash -c "..." and sh -c "..." strings, then executes them via child_process.exec(). An authenticated admin/owner can inject arbitrary OS commands that execute on the host machine running Dokploy (not just inside a container). This vulnerability is fixed in 0.29.13.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked at 2 mentions on most recent observed day (2026-09-18)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-11: 1Mentions · 2026-09-18: 2Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-09-18: 2Technical Details · 2026-08-11: 1Technical Details · 2026-09-18: 208-1109-18
Signal classification1 categories
Patch
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-111
Patch1
2026-09-182
Patch2
Full discourse3 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    A critical Dokploy OS command injection flaw (CVE-2026-72878) exposes servers to root takeover via backups. Patch this Dokploy OS command injection now. #Dokploy #CommandInjection #CVE202672878 #Cybersecurity #PaaS https://securityonline.info/dokploy-os-command-injection/

    Post summary

    The tweet describes a critical OS command injection flaw in Dokploy (CVE-2026-72878) enabling root takeover via backups and urges immediate patching.

    11040519
    13.0K followersView on X
  • NEXSIGHT@NEXSIGHTNEWS
    Patch

    セルフホスト型PaaS「Dokploy」にOSコマンドインジェクション — バックアップ権限を持つ利用者がroot権限でコマンドを実行できる脆弱性、CVE-2026-72878として追跡され0.29.13で修正 https://cyber.nexsight.co/articles/2026/09/18/dokploy-os-command-injection-cve-2026-72878-2026-09-18/

    Post summary

    Dokploy OS command injection CVE-2026-72878 (backup user to root) with a fixed version 0.29.13 named; no PoC, exploit tool, or active exploitation reported.

    0000057
    74 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    controlled fields into shell commands, allowing authenticated admins to execute OS-level commands on the host. CVSS 9.6. Update to 0.29.13 immediately. #CVE #Dokploy #infosec https://www.valtersit.com/cve/CVE-2026-72878/ #SysAdmin #cybersecurity #CVE #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #chezck #japan #soudarabia

    Post summary

    The post announces a critical vulnerability (CVSS 9.6) that enables authenticated admins to run OS‑level commands in Dokploy and urges users to update to version 0.29.13 immediately.

    0000046
    1.0K followersView on X

Explore more