In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://advisories.octopus.com/post/2026/sa2026-13 |
|
History
Thu, 01 Oct 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary Script Execution Through Scoped Permission Flaws in Octopus Server |
Thu, 01 Oct 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Octopus
Published:
Updated: 2026-10-01T04:36:23.243Z
Reserved: 2026-08-24T01:59:35.230Z
Link: CVE-2026-78210
No data.
Status : Received
Published: 2026-10-01T05:17:10.117
Modified: 2026-10-01T05:17:10.117
Link: CVE-2026-78210
No data.
OpenCVE Enrichment
Updated: 2026-10-01T05:45:17Z
Weaknesses