CVE-2026-45661 @ mufasa
Status
does_not_affect
Priority
8.04
Match score
2.5
Risk
RCE
CVSS
9.9 CRITICAL
Reason
packages: filesystem
Created
2026-08-02T02:52:04Z
Updated
2026-08-02T08:42:02Z
Closed
2026-08-02T08:42:02Z
Package interrogation (copy)
Run on the host — click to copy a command. RPM
| Package | Commands |
|---|---|
| filesystem |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: filesystem
| System | Matches | Ticket for CVE-2026-45661 | |
|---|---|---|---|
| morris | emacs-filesystem 24.3; filesystem 3.2; firebird-filesystem 2.5.9.27139.0; firewalld-filesystem 0.6.3; fontpackages-filesystem 1.44; plesk-libboost-filesystem1.65 1.65.1; plesk-libboost-filesystem1.74 1.74.0.1; plesk-libboost-filesystem1.82 1.82.0 (+1 more) | does_not_affect open | |
| mufasa | emacs-filesystem 24.3; filesystem 3.2; firebird-filesystem 2.5.9.27139.0; firewalld-filesystem 0.6.3; fontpackages-filesystem 1.44; libreport-filesystem 2.1.11; plesk-libboost-filesystem1.74 1.74.0.1; plesk-libboost-filesystem1.82 1.82.0 (+2 more) | does_not_affect open | |
| Helios | libboost-filesystem1.74.0 1.74.0-9 | none | |
| Saiph | libboost-filesystem1.55.0 1.55.0+dfsg-3; libboost-filesystem1.62.0 1.62.0+dfsg-4 | none |
Same product CVEs in your queue
Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.
| CVE | CVSS | KEV | Systems | Status | Matched | Already related | |
|---|---|---|---|---|---|---|---|
| CVE-2026-67429 | 10.0 | morris, mufasa | does_not_affect | filesystem | — | ||
| CVE-2026-68770 | 9.8 | morris, mufasa | does_not_affect | filesystem | — | ||
| CVE-2025-40212 | 9.8 | morris, mufasa | not_applicable | filesystem | — | ||
| CVE-2026-36829 | 9.8 | morris, mufasa | does_not_affect | filesystem | — | ||
| CVE-2026-25879 | 9.8 | morris, mufasa | does_not_affect | filesystem | — | ||
| CVE-2026-47162 | 8.8 | Archive, Janus, Library, Matrix, Saiph | accepted_risk | filesystem | — | ||
| CVE-2023-4692 | 7.5 | Archive, Janus, Library, Saiph, morris … | accepted_risk, fixed | filesystem | — |
Related CVE (same fix)
Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.
Host OS / kernel
OS
CloudLinux release 7.9 (Boris Yegorov)
(7.9)
· cloudlinux
Arch
x86_64
kernel_release
uname -r → 3.10.0-962.3.2.lve1.5.89.el7.x86_64kernel_version
uname -v → #1 SMP Thu Jul 9 15:55:31 UTC 2026For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| morris | does_not_affect | 8.04 | 2026-08-02T08:41:47Z | Open |
Description
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during application deployment. When combined with Dokploy's remote server deployment feature, this vulnerability enables arbitrary file write to remote server filesystems, automatic remote code execution via cron jobs, complete server compromise, data exfiltration without user interaction, and persistent backdoor installation. This vulnerability bypasses all container isolation on remote server deployments.
Determination
no product
Update status
Add note only
Mitigation log
2026-08-02T08:42:02Z — does_not_affect
no product
References
- https://github.com/Dokploy/dokploy/security/advisories/GHSA-66v7-g3fh-47h3
- https://github.com/Dokploy/dokploy/security/advisories/GHSA-66v7-g3fh-47h3
NVD: CVE-2026-45661