CVE-2021-26556: High severity octopus deploy vulnerability
When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26556?
CVE-2021-26556 is classified as a high severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2021-26556?
To fix CVE-2021-26556, ensure that proper ACLs are set on the installation folders of Octopus Server.
Who is affected by CVE-2021-26556?
CVE-2021-26556 affects users who have installed Octopus Server or Octopus Deploy in custom folder locations without the correct folder ACLs.
What type of attack can CVE-2021-26556 enable?
CVE-2021-26556 can enable DLL side-loading attacks allowing unprivileged users to execute malicious code with elevated privileges.
What versions of Octopus Deploy are affected by CVE-2021-26556?
CVE-2021-26556 affects Octopus Deploy versions up to 2020.4.229 and Octopus Server versions between 2020.5.0 and 2020.5.256.