Skip to content
Critical RCE Vulnerabilities Discovered in Dokploy and Omni C20 Systems

Critical RCE Vulnerabilities Discovered in Dokploy and Omni C20 Systems

First seen 26 Sep 2026, 07:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 16:34 UTC
  • •CVE-2026-93425 allows root command execution in Dokploy containers.
  • •CVE-2026-93291 enables MITM attacks on Omni C20 systems due to certificate validation flaws.
  • •Both vulnerabilities are rated critical, with no public exploits available yet.

Two critical vulnerabilities, CVE-2026-93425 and CVE-2026-93291, were disclosed on September 24, 2026. CVE-2026-93425 affects Dokploy PaaS, allowing authenticated users to execute arbitrary commands as root within containers, potentially compromising the host. The vulnerability arises from unsafe shell argument quoting in the patch.readRepoDirectories procedure. CVE-2026-93291 impacts Omni C20 systems, enabling man-in-the-middle attacks due to improper certificate validation, leading to remote code execution. Both vulnerabilities have a CVSS severity rating of 9.9 and 9.4, respectively, and no public proof-of-concept exploits are available yet. Security advisories are under review, and organizations are urged to monitor for anomalous activity. The attack vectors for both vulnerabilities require specific conditions, with CVE-2026-93425 needing authenticated access and CVE-2026-93291 requiring network access for MITM attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-24
CVE-2026-93425 published
Critical command injection vulnerability in Dokploy PaaS disclosed, allowing root access in containers.
TheHackerWire
2026-09-24
CVE-2026-93291 published
Critical certificate validation flaw in Omni C20 systems disclosed, enabling MITM attacks.
TheHackerWire
2026-09-26
Advisory status under review
Remediation status for both vulnerabilities is currently under advisory and mitigation review.
TheHackerWire

More articles in this cluster (2)

Following this threat?

Track CVE-2026-78312 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed