Junglewise Threat Intelligence

CVE-2026-43917: Dokploy cross-organization IDOR in multiple tRPC endpoints

CVE-2026-43917 · Severity: info · CVSS 5.3 · Published 2026-05-29

Technologies: Dokploy. Vendors: Dokploy.

Executive brief

Dokploy is a self-hostable platform used to manage and deploy applications and infrastructure. A security flaw in its organization management system allows an authenticated user from one organization to view, modify, or delete resources belonging to a different organization. This could lead to unauthorized access to server details, the termination of production deployments, or the deletion of critical backups.

Technical details

Multiple tRPC endpoints in Dokploy suffer from an Insecure Direct Object Reference (IDOR) vulnerability. While the 'protectedProcedure' middleware confirms a user is authenticated, it does not automatically enforce organization-level isolation. Over 25 endpoints (including those for deployments, backups, rollbacks, and cluster management) fail to manually verify that the requested resource ID belongs to the user's 'activeOrganizationId'. An attacker with a valid account in one organization can manipulate resource IDs in API calls to kill processes, delete backups, or retrieve Docker Swarm join tokens belonging to other organizations on the same instance. Affected files include deployment.ts, backup.ts, cluster.ts, and others.

Affected products

  • Dokploy Dokploy <= 0.19.0

Timeline

  • 2026-05-11: advisory: GitHub Security Advisory published by maintainer
  • 2026-05-29: disclosed: CVE published to NVD

References

Related threats