CVE-2017-15611: Octopus Deploy

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserInvite) can invite users to teams with escalated privileges.

Affected products

  • Octopus Octopus Deploy: up to and including 3.17.6

Published 2017-10-19. Last modified 2026-06-17.