Description
In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the user possessing the required authorisation.
Published: 2026-09-15
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Script Execution
Action: Apply Patch
AI Analysis

Impact

In certain Octopus Server versions, a flaw in permission validation allowed users with specific scoped permission sets to run arbitrary scripts on a worker, including the built‑in worker, without the required authorisation, effectively giving by the worker and exposing the system to serious compromise.

Affected Systems

The vulnerability affects Octopus Server deployments that include the built‑in worker; any instance where users are assigned permission sets that enable script execution is at risk, but no specific version range is provided in the advisory.

Risk and Exploitability

The CVSS score of 7.2 indicates moderate to high severity, the EPSS score of less than 1% suggests a low current exploitation probability, and it is not listed in the CISA attackers could exploit the weakness if authorization checks are bypassed, potentially leading to remote code execution on the worker process, with the likely attack vector being a legitimate user account that has unauthorized script execution permissions and the vulnerability inferred to be exploitable through normal application interaction giving the attacker control over script parameters.

Generated by OpenCVE AI on September 17, 2026 at 18:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Octopus Server patch that rectifies the permission validation check for script execution.
  • If a patch is not immediately available, revoke or limit the scoped permission sets that grant the measure.
  • Restrict user accounts to the least privilege principle and review role assignments to eliminate unnecessary script execution rights.
  • Monitor logs for unexpected script activity and investigate any anomalies promptly.

Generated by OpenCVE AI on September 17, 2026 at 18:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Arbitrary Script Execution via Permission Validation Bypass in Octopus Server

Wed, 16 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Arbitrary Script Execution via Permission Validation Bypass in Octopus Server

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the user possessing the required authorisation.
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Octopus

Published:

Updated: 2026-09-15T14:40:42.112Z

Reserved: 2026-09-15T01:38:15.839Z

Link: CVE-2026-91778

cve-icon Vulnrichment

Updated: 2026-09-15T14:40:07.249Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T08:17:07.180

Modified: 2026-09-16T19:41:10.423

Link: CVE-2026-91778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses