Junglewise Threat Intelligence

CVE-2026-45632: Dokploy authorization bypass and RCE in schedule router

CVE-2026-45632 · Severity: critical · CVSS 9.9 · Published 2026-05-29

Technologies: Dokploy. Vendors: Dokploy.

Executive brief

Dokploy is a self-hostable platform used to manage and deploy applications. A security flaw in its scheduling component allows any registered user to bypass organizational restrictions and execute arbitrary commands on the host server or connected remote servers. This could lead to a total system takeover, unauthorized data access, or the complete deletion of managed services and schedules.

Technical details

A missing authorization check in the Dokploy schedule router (apps/dokploy/server/api/routers/schedule.ts) allows any authenticated user to perform CRUD operations on schedules across different organizations. By providing a specific scheduleId or serverId, an attacker can create or modify schedules of type 'server' or 'dokploy-server'. These schedule types are designed to write and execute scripts on the filesystem. Because the application fails to validate organization/role ownership or restrict these high-privilege schedule types to administrators, a low-privileged user can achieve Remote Code Execution (RCE) on the Dokploy host or any registered remote server. As of the advisory date, no patched version is listed.

Affected products

  • Dokploy Dokploy <= 0.26.7

Timeline

  • 2026-05-11: advisory: Original GitHub security advisory published
  • 2026-05-29: disclosed: CVE published to NVD

References

Related threats