CVE-2026-72880Disclosure

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/certificate.ts accepts a client-supplied certificatePath, and packages/server/src/services/certificate.ts joins that value to the certificate root without confinement. An authenticated user with certificate create or delete permission can use certificatePath to write attacker-controlled certificate content outside the intended directory or delete an out-of-root directory. This vulnerability is fixed in 0.29.13.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-11); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-11: 1Mentions · 2026-08-14: 1Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-14: 108-1108-14
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-111
Disclosure1
2026-08-141
Patch1
Full discourse2 posts
  • HOL@HashgraphOnline
    Patch

    CVE-2026-72880: Dokploy's certificatePath field accepts user input without confining it to the certificate root. An authenticated user can write files anywhere on the host or execute arbitrary OS commands. Fixed in 0.29.13. Upgrade now if you run Dokploy. https://hol.org/blog/cve-2026-72880-dokploy-cert-path-traversal-rce

    Post summary

    The advisory announces a path-traversal remote code execution flaw in Dokploy, highlights that version 0.29.13 contains a fix, and provides basic technical details of the vulnerability.

    010701.0K
    19.2K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-72880 - Critical path traversal in Dokploy PaaS. Unpatched; authenticated users can write/delete files outside cert dir via certificatePath. CVSS 9.9. Update or restrict access immediately. https://www.valtersit.com/cve/CVE-2026-72880 #CVE #Dokploy #infosec #CVE #Dokploy #infosec #CVE #Linux #infosec #infosec #cybersecurity #CVE #Linux #infosec #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland

    Post summary

    CVE-2026-72880 is a critical path‑traversal flaw in Dokploy PaaS allowing authenticated users to modify files outside the certificate directory. Immediate update or access restriction is advised.

    0000054
    1.0K followersView on X

Explore more