Security Advisory

CVE-2026-24839

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-28 00:01:49
Last updated 2026-01-28 15:02:29
Assigner GitHub_M
State PUBLISHED

Description

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages in malicious iframes and trick authenticated users into performing unintended actions. Version 0.26.6 patches the issue.