CVE-2026-102478: Octopus Deploy Octopus Server
High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.
In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to improper validation of unsafe equivalence in inputs.
Affected products
- Octopus Deploy Octopus Server: from 2023.2.945, before 2026.1.11768 (fixed in 2026.1.11768); from 2026.2.0, before 2026.2.13408 (fixed in 2026.2.13408); from 2026.3.0, before 2026.3.15816 (fixed in 2026.3.15816)
Published 2026-10-07. Last modified 2026-10-07.