CVE-2026-12878: High severity Codefresh platform vulnerability
Published Aug 25, 2026
·Updated
In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.
Affected Software
4 affected components
Codefresh platform
All of the following
Octopus Codefresh>=2.0.0<2.11.15
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Aug 25, 2026
CVE Published
via MITRE·09:02 AM
Data Sourced
via MITRE·09:02 AM
DescriptionWeakness
Data Sourced
via NVD·10:18 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must already be authenticated to the Codefresh platform. The issue allows that authenticated user to elevate their permissions to Admin.
2
Who should treat this as exposed?
Codefresh platform deployments running affected versions are exposed if authenticated users can access the vulnerable API endpoint. The provided information does not identify which versions are affected or whether any particular default configuration enables the endpoint.