CVE-2026-102488: High severity Octopus Deploy Octopus Server vulnerability
In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need?
The issue requires an authenticated user with privileges. The description specifically identifies a highly privileged user as the party that can obtain deployment permissions beyond those granted.
Does exploitation require user interaction or local access?
No user interaction is required, and the vector is network-based. An attacker would need access to the Octopus Server and suitable existing privileges.
What is the practical impact of successful exploitation?
A highly privileged user may gain deployment permissions outside their intended scope because multiple scoped permission assignments are evaluated incorrectly. The CVSS vector indicates high impact to confidentiality, integrity, and availability.