CVE-2026-12878
Received Received - Intake

Authenticated Privilege Escalation in Codefresh Platform

Vulnerability report for CVE-2026-12878, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: Octopus Deploy

Description

In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
codefresh codefresh to 2.11.15 (exc)
codefresh codefresh 2.11.18

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated user in the Codefresh platform to exploit an API endpoint and elevate their permissions to admin level. It affects Codefresh versions prior to 2.11.15.

Detection Guidance

Check Codefresh version with: curl -s https://<codefresh-domain>/api/version | grep version. If version is below 2.11.15, the system is vulnerable.

Impact Analysis

An attacker with valid credentials could gain admin access, potentially allowing them to modify configurations, access sensitive data, or disrupt operations within the Codefresh platform.

Mitigation Strategies

Upgrade Codefresh to version 2.11.15 or higher immediately. No workarounds exist, so patching is critical to prevent privilege escalation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12878. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart