CVE-2026-78210

Summary

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization.

Affected Software

VendorProductVersion RangeStatus
Octopus DeployOctopus Server2019.5.9 < 2026.1.11739affected
Octopus DeployOctopus Server2026.2.0 < 2026.2.13364affected
Octopus DeployOctopus Server2026.3.0 < 2026.3.13951affected

Weaknesses

  • CWE-863: CWE-863: Incorrect Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References