CVE-2026-4881: Medium severity Octopus Deploy Octopus Server vulnerability
In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4881?
CVE-2026-4881 has a medium severity rating of 6.
What is CVE-2026-4881 about?
CVE-2026-4881 involves improper permissions checks in Octopus Server, allowing authenticated users to make unauthorized server level changes.
How do I fix CVE-2026-4881?
To fix CVE-2026-4881, ensure that your Octopus Server is updated to the latest version provided by Octopus Deploy that addresses this vulnerability.
Who is impacted by CVE-2026-4881?
Any authenticated user of affected versions of Octopus Server could be impacted by CVE-2026-4881 due to the lack of proper permissions checks.
What should I do if I am using an affected version of Octopus Server?
If you are using an affected version of Octopus Server, you should update to a version that has resolved CVE-2026-4881 as soon as possible.