CVE-2026-4881: Octopus Server
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.
Affected products
- Octopus Octopus Server: from 2023.1.4189, before 2025.4.10545 (fixed in 2025.4.10545); from 2026.1.675, before 2026.1.11313 (fixed in 2026.1.11313)
Published 2026-06-04. Last modified 2026-07-22.