Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages in malicious iframes and trick authenticated users into performing unintended actions. Version 0.26.6 patches the issue.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-28 01:16
Updated : 2026-01-29 16:31
NVD link : CVE-2026-24839
Mitre link : CVE-2026-24839
CVE.ORG link : CVE-2026-24839
JSON object : View
Products Affected
No product.
CWE
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
