Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages in malicious iframes and trick authenticated users into performing unintended actions. Version 0.26.6 patches the issue.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 28 Jan 2026 09:30:00 +0900

Type Values Removed Values Added
Description Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages in malicious iframes and trick authenticated users into performing unintended actions. Version 0.26.6 patches the issue.
Title Dokploy has a clickjacking vulnerability - Missing X-Frame-Options and CSP frame-ancestors headers
Weaknesses CWE-1021
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-28T00:01:49.253Z

Reserved: 2026-01-27T14:51:03.059Z

Link: CVE-2026-24839

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-28T01:16:14.490

Modified: 2026-01-28T01:16:14.490

Link: CVE-2026-24839

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses