CVE-2020-10678: Octopus Deploy

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can leverage a bug to escalate privileges.

Affected products

  • Octopus Octopus Deploy: before 2020.1.5 (fixed in 2020.1.5)

Published 2020-03-19. Last modified 2026-06-17.