CVE-2018-5706: Octopus Deploy
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
An issue was discovered in Octopus Deploy before 4.1.9. Any user with user editing permissions can modify teams to give themselves Administer System permissions even if they didn't have them, as demonstrated by use of the RoleEdit or TeamEdit permission.
Affected products
- Octopus Octopus Deploy: before 4.1.9 (fixed in 4.1.9)
Published 2018-01-16. Last modified 2026-06-17.