CVE-2026-3237: Octopus Server
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via an API endpoint that had incorrect permission validation. It was not possible to expose the signing keys using this vulnerability.
Affected products
- Octopus Octopus Server: before 2025.3.14731 (fixed in 2025.3.14731); from 2025.4.51, before 2025.4.10359 (fixed in 2025.4.10359); from 2026.1.675, before 2026.1.5571 (fixed in 2026.1.5571)
Published 2026-03-17. Last modified 2026-06-17.