{"apiVersion":"1.0","identifier":"CVE-2026-45790","description":"Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy-s organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user with member:create permission to invite an account with the owner role, while packages/server/src/services/user.ts allows a privileged self-hosted user to create an account with an arbitrary role, enabling permanent organization takeover because owner roles cannot be demoted. This issue is fixed in version 0.29.6.","publishedAt":"2026-08-17T22:17:14","lastModifiedAt":"2026-08-18T16:17:09","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-45790","cvssScore":8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","epssProbability":0.00284,"riskScore":0.82,"affectedProduct":"Dokploy","affectedVersions":"<0.29.6","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-45790","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-45790","en":"https://www.redsauce.net/en/cves/CVE-2026-45790","fr":"https://www.redsauce.net/fr/cves/CVE-2026-45790","pt":"https://www.redsauce.net/pt/cves/CVE-2026-45790","de":"https://www.redsauce.net/de/cves/CVE-2026-45790","sk":"https://www.redsauce.net/sk/cves/CVE-2026-45790","el":"https://www.redsauce.net/el/cves/CVE-2026-45790"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-45790"}}