CVE-2026-91778: Octopus Server vulnerability
Published Sep 15, 2026
·Updated
In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the user possessing the required authorisation.
Affected Software
1 affected component
Octopus Server
Event History
Sep 15, 2026
CVE Published
via MITRE·07:05 AM
Data Sourced
via MITRE·07:05 AM
DescriptionWeakness
Frequently Asked Questions
1
Who would need access to exploit this issue?
The issue applies to users with certain scoped permission sets. Those users may be able to execute scripts without having the authorisation normally required for script execution.
2
What systems could a successful script execution affect?
A script can execute on a worker, including the Octopus Server built-in worker.