CVE-2021-26557: High severity octopus tentacle vulnerability
Published Oct 7, 2021
·Updated
When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.
Affected Software
1 affected component
Octopus Tentacle>=3.15.4<6.0.489
Event History
Oct 7, 2021
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-26557?
CVE-2021-26557 is considered a high severity local privilege escalation vulnerability.
2
How do I fix CVE-2021-26557?
To fix CVE-2021-26557, ensure correct ACLs are set on the installation folder of Octopus Tentacle.
3
Who is affected by CVE-2021-26557?
CVE-2021-26557 affects users who installed Octopus Tentacle in a custom folder location without proper folder permissions.
4
What could an attacker exploit in CVE-2021-26557?
An attacker could exploit CVE-2021-26557 to use DLL side-loading to gain elevated privileges on the system.
5
What versions of Octopus Tentacle are vulnerable to CVE-2021-26557?
Octopus Tentacle versions between 3.15.4 and 6.0.489 are vulnerable to CVE-2021-26557.