Description
In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them.
Published: 2026-10-08
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

This vulnerability allows a user already possessing high‑privilege levels in Octopus Server to acquire additional deployment permissions that exceed what their role explicitly grants. The flaw stems from the server’s incorrect handling of scoped permission assignments, leading to an authorization bypass. The attacker can gain elevated capabilities to deploy builds, potentially compromising application integrity.

Affected Systems

Octopus Deploy Octopus Server is affected. Specific versions are not disclosed in the advisory, but all released versions before the advisory date contain the flaw.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity. EPSS data is not available, and the flaw is not listed in CISA KEV. Availability of the vulnerability likely requires an authenticated user with some privilege; the attacker can leverage the internal permission system of Octopus Server to elevate rights. Given the lack of external exploitation requirements, the risk is primarily to organizations that allow users to access the Octopus Server with any management privileges.

Generated by OpenCVE AI on October 8, 2026 at 02:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Octopus Server to the latest version that resolves the permission evaluation bug as announced by the vendor.
  • Revoke any unnecessary deployment permissions from privileged accounts and reassign only the required levels in accordance with the principle of least privilege.
  • Enable audit logging for permission changes and monitor privileged account activity to detect any anomalous escalation attempts.

Generated by OpenCVE AI on October 8, 2026 at 02:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Permission Evaluation in Octopus Server

Thu, 08 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Description In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them.
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Octopus

Published:

Updated: 2026-10-08T01:38:57.175Z

Reserved: 2026-09-29T09:36:59.981Z

Link: CVE-2026-102488

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T02:16:53.003

Modified: 2026-10-08T02:16:53.003

Link: CVE-2026-102488

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T02:30:06Z

Weaknesses