CVE-2026-102478 PUBLISHED

Assigner: Octopus
Reserved: 29.09.2026 Published: 07.10.2026 Updated: 07.10.2026

In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to improper validation of unsafe equivalence in inputs.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Octopus Deploy
Product Octopus Server
Versions Default: unaffected
  • affected from 2023.2.945 to 2026.1.11768 (excl.)
  • affected from 2026.2.0 to 2026.2.13408 (excl.)
  • affected from 2026.3.0 to 2026.3.15816 (excl.)

Credits

  • This vulnerability was found by Nathan Willoughby finder

References

Problem Types

  • CWE-1289: Improper Validation of Unsafe Equivalence in Input CWE