First published: Thu Oct 07 2021(Updated: )
When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.
Credit: security@octopus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Tentacle | >=3.15.4<6.0.489 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26557 is considered a high severity local privilege escalation vulnerability.
To fix CVE-2021-26557, ensure correct ACLs are set on the installation folder of Octopus Tentacle.
CVE-2021-26557 affects users who installed Octopus Tentacle in a custom folder location without proper folder permissions.
An attacker could exploit CVE-2021-26557 to use DLL side-loading to gain elevated privileges on the system.
Octopus Tentacle versions between 3.15.4 and 6.0.489 are vulnerable to CVE-2021-26557.