www.thehackerwire.com Critical RCE Vulnerabilities Discovered in Dokploy and Omni C20 Systems
Article Content
- •CVE-2026-93425 allows root command execution in Dokploy containers.
- •CVE-2026-93291 enables MITM attacks on Omni C20 systems due to certificate validation flaws.
- •Both vulnerabilities are rated critical, with no public exploits available yet.
Two critical vulnerabilities, CVE-2026-93425 and CVE-2026-93291, were disclosed on September 24, 2026. CVE-2026-93425 affects Dokploy PaaS, allowing authenticated users to execute arbitrary commands as root within containers, potentially compromising the host. The vulnerability arises from unsafe shell argument quoting in the patch.readRepoDirectories procedure. CVE-2026-93291 impacts Omni C20 systems, enabling man-in-the-middle attacks due to improper certificate validation, leading to remote code execution. Both vulnerabilities have a CVSS severity rating of 9.9 and 9.4, respectively, and no public proof-of-concept exploits are available yet. Security advisories are under review, and organizations are urged to monitor for anomalous activity. The attack vectors for both vulnerabilities require specific conditions, with CVE-2026-93425 needing authenticated access and CVE-2026-93291 requiring network access for MITM attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-78312 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed