CVE-2026-24839

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages in malicious iframes and trick authenticated users into performing unintended actions. Version 0.26.6 patches the issue.
Configurations

No configuration.

History

No history.

Information

Published : 2026-01-28 01:16

Updated : 2026-01-29 16:31


NVD link : CVE-2026-24839

Mitre link : CVE-2026-24839

CVE.ORG link : CVE-2026-24839


JSON object : View

Products Affected

No product.

CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames