CVE-2026-3236: Octopus Server
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token.
Affected products
- Octopus Octopus Server: from 2023.1.4189, before 2025.3.14761 (fixed in 2025.3.14761); from 2025.4.51, before 2025.4.10409 (fixed in 2025.4.10409)
Published 2026-03-05. Last modified 2026-06-17.