Home
MEDIUM: 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
2023.0.0 (custom) before 2025.4.10523
affected
2025.4.0 (custom) before 2025.4.10545
affected
2026.1.0 (custom) before 2026.1.11313
affected
Description
In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.
Problem types
Insufficient permission checks on an API endpoint
Product status
2023.0.0 (custom) before 2025.4.10523
2025.4.0 (custom) before 2025.4.10545
2026.1.0 (custom) before 2026.1.11313
Credits
This vulnerability was found by MononcleMich
References
advisories.octopus.com/post/2026/sa2026-04