Impact
This vulnerability allows a user already possessing high‑privilege levels in Octopus Server to acquire additional deployment permissions that exceed what their role explicitly grants. The flaw stems from the server’s incorrect handling of scoped permission assignments, leading to an authorization bypass. The attacker can gain elevated capabilities to deploy builds, potentially compromising application integrity.
Affected Systems
Octopus Deploy Octopus Server is affected. Specific versions are not disclosed in the advisory, but all released versions before the advisory date contain the flaw.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. EPSS data is not available, and the flaw is not listed in CISA KEV. Availability of the vulnerability likely requires an authenticated user with some privilege; the attacker can leverage the internal permission system of Octopus Server to elevate rights. Given the lack of external exploitation requirements, the risk is primarily to organizations that allow users to access the Octopus Server with any management privileges.
OpenCVE Enrichment