CVE-2022-1670: Octopus Server

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validity to create extra user accounts above the initial number of invited users.

Affected products

  • Octopus Octopus Server: from 0.9, before 2021.3.12533 (fixed in 2021.3.12533); from 2022.1.0, before 2022.1.53 (fixed in 2022.1.53)

Published 2022-05-19. Last modified 2026-06-17.