Impact
In certain Octopus Server versions, a flaw in permission validation allowed users with specific scoped permission sets to run arbitrary scripts on a worker, including the built‑in worker, without the required authorisation, effectively giving by the worker and exposing the system to serious compromise.
Affected Systems
The vulnerability affects Octopus Server deployments that include the built‑in worker; any instance where users are assigned permission sets that enable script execution is at risk, but no specific version range is provided in the advisory.
Risk and Exploitability
The CVSS score of 7.2 indicates moderate to high severity, the EPSS score of less than 1% suggests a low current exploitation probability, and it is not listed in the CISA attackers could exploit the weakness if authorization checks are bypassed, potentially leading to remote code execution on the worker process, with the likely attack vector being a legitimate user account that has unauthorized script execution permissions and the vulnerability inferred to be exploitable through normal application interaction giving the attacker control over script parameters.
OpenCVE Enrichment