External risk intelligence

Dokploy Provider Credential Exposure Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-86059

Dokploy is a self-hostable Platform as a Service (PaaS) designed to manage deployments and infrastructure. As a centralized management platform for applications and external service integrations, it is commonly deployed as an internet-facing or network-accessible service to facilitate remote management, developer access, and CI/CD operations.

Information Disclosure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in Dokploy, a self-hostable platform used for managing application deployments. The issue allows certain users within an organization to access sensitive Git provider credentials, such as API tokens and secrets, even without explicit permissions. This could potentially enable unauthorized access to private code repositories or manipulation of external development workflows.

  • Stolen credentials could expose private code.
  • Affects self-hosted deployment management services.
  • Confirm exposure and relevance for security review.

Attack Path

How an attacker could exploit the issue

An attacker with an organization membership in Dokploy can retrieve sensitive Git provider credentials. This occurs because specific API endpoints expose full provider details without proper access controls, even when the member lacks direct Git provider access. The vulnerability allows bypassing per-member assignments, enabling the attacker to use the exposed credentials to access private code repositories or alter external automated workflows.

  • Organization membership required.
  • Exposed Git provider credentials.
  • Access to private code and workflows.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, organization members without Git provider access could retrieve plaintext provider credentials and GitHub App private keys. This could enable unauthorized access to private repositories or manipulation of external workflows.

  • Git provider credentials and private keys.
  • Through protected procedures and routes.
  • Unauthorized repository access or workflow manipulation.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Dokploy PaaS deployments, potentially exposing Git provider credentials and GitHub App private keys to unauthorized organization members. The first step is to identify all Dokploy instances, confirm their network exposure and business criticality, and then locate the accountable owner for remediation planning.

  • Platform/Application owners should investigate.
  • Verify Dokploy instance exposure and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Dokploy?

Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies managing application deployments and infrastructure. It acts as a central hub where developers can connect Git providers like GitHub or GitLab to automate their CI/CD pipelines, container orchestration, and server management tasks in one place.

What kind of security weakness is CVE-2026-86059?

This vulnerability involves Improper Authorization (CWE-862) and Exposure of Sensitive Information to an Unauthorized Actor (CWE-200). Essentially, the software fails to check if a user has the correct permissions before revealing sensitive data. In this case, Dokploy provides full access to internal Git provider secrets and OAuth tokens to users who should not be able to view or use them.

How does an attacker trigger this vulnerability?

An attacker needs to be an existing member of a Dokploy organization. The bug is triggered when they access specific API routes that return provider details without validating the user's permissions. Simply browsing the platform normally or having standard read access to an application is enough to expose the credentials. Public, unauthenticated users who are not part of the organization cannot trigger this bug.

Is my Dokploy instance at risk?

According to Halo Surface Signal, Dokploy is often deployed as an internet-facing service to support remote teams and automated workflows, which increases the likelihood that these credentials could be reached remotely. If your instance is accessible over the internet, any compromised or malicious organization member can reach these API routes to steal private repository keys and workflow secrets.

Do I need to update my software?

Yes. The vulnerability is resolved in Dokploy version 0.29.13. If you are running an earlier version, you should prioritize upgrading to this release immediately. After updating, ensure that all Git provider credentials are secure and consider rotating any sensitive API tokens or private keys that were stored in the platform while it was running an older, vulnerable version.

References