In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the user possessing the required authorisation.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://advisories.octopus.com/post/2026/sa2026-08 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 08:17
Updated : 2026-09-15 15:17
NVD link : CVE-2026-91778
Mitre link : CVE-2026-91778
CVE.ORG link : CVE-2026-91778
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
