CVE-2026-4881
Awaiting Analysis
Awaiting Analysis - Queue
Authenticated API Access Bypass in Octopus Server
Publication date: 2026-06-04
Last updated on: 2026-06-04
Assigner: Octopus Deploy
Description
Description
In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| octopus | server | to 2025.4.10545 (exc) |
| octopus | server | to 2026.1.11313 (exc) |
| octopus | server | 2026.1.11481 |
| octopus | server | From 2023.0.0 (inc) to 2025.1.0 (exc) |
| octopus | server | From 2024.0.0 (inc) to 2025.1.0 (exc) |
| octopus | server | From 2025.1.0 (inc) to 2025.4.0 (exc) |
| octopus | server | From 2025.2.0 (inc) to 2025.4.0 (exc) |
| octopus | server | From 2025.3.0 (inc) to 2025.4.0 (exc) |
| octopus | server | From 2025.4.0 (inc) to 2025.4.10545 (exc) |
| octopus | server | From 2026.1.0 (inc) to 2026.1.11313 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |