CVE-2024-4226: Octopus Server

Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.

It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.

Affected products

  • Octopus Octopus Server: from 2022.2.6729, before 2022.2.7934 (fixed in 2022.2.7934); from 2022.3.348, before 2022.3.9163 (fixed in 2022.3.9163)

Published 2024-04-30. Last modified 2026-06-17.