CVE-2026-78210: Octopus Deploy Octopus Server
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization.
Affected products
- Octopus Deploy Octopus Server: from 2019.5.9, before 2026.1.11739 (fixed in 2026.1.11739); from 2026.2.0, before 2026.2.13364 (fixed in 2026.2.13364); from 2026.3.0, before 2026.3.13951 (fixed in 2026.3.13951)
Published 2026-10-01. Last modified 2026-10-01.