CVE-2026-91778: Octopus Deploy Octopus Server
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the user possessing the required authorisation.
Affected products
- Octopus Deploy Octopus Server: from 2019.0.0, before 2026.1.11725 (fixed in 2026.1.11725); from 2026.2.0, before 2026.2.13344 (fixed in 2026.2.13344); from 2026.3.0, before 2026.3.11816 (fixed in 2026.3.11816)
Published 2026-09-15. Last modified 2026-09-16.