CVE-2026-102488: Octopus Deploy Octopus Server
High severity, CVSS 8.7. EPSS: 0.2% chance of exploitation in the next 30 days.
In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them.
Affected products
- Octopus Deploy Octopus Server: from 2019.5.0, before 2026.2.12438 (fixed in 2026.2.12438); from 2026.3.0, before 2026.3.15816 (fixed in 2026.3.15816)
Published 2026-10-08. Last modified 2026-10-08.