Description
In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to improper validation of unsafe equivalence in inputs.
Published: 2026-10-07
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 04:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Unrestricted Role Modification in Octopus Server

Wed, 07 Oct 2026 02:00:00 +0000

Type Values Removed Values Added
Description In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to improper validation of unsafe equivalence in inputs.
Weaknesses CWE-1289
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Octopus

Published:

Updated: 2026-10-07T01:17:54.724Z

Reserved: 2026-09-29T08:53:05.496Z

Link: CVE-2026-102478

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T02:16:56.320

Modified: 2026-10-07T02:16:56.320

Link: CVE-2026-102478

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T03:45:10Z

Weaknesses
  • CWE-1289

    Improper Validation of Unsafe Equivalence in Input