CVE-2026-24839: Dokploy
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages in malicious iframes and trick authenticated users into performing unintended actions. Version 0.26.6 patches the issue.
Affected products
- Dokploy Dokploy: before 0.26.6 (fixed in 0.26.6)
Published 2026-01-28. Last modified 2026-06-17.