CVE-2026-102478

Summary

In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to improper validation of unsafe equivalence in inputs.

Affected Software

VendorProductVersion RangeStatus
Octopus DeployOctopus Server2023.2.945 < 2026.1.11768affected
Octopus DeployOctopus Server2026.2.0 < 2026.2.13408affected
Octopus DeployOctopus Server2026.3.0 < 2026.3.15816affected

Weaknesses

  • CWE-1289: CWE-1289: Improper Validation of Unsafe Equivalence in Input

References