CVE-2026-102478
Received
Received - Intake
Privilege Escalation in Octopus Server via Role Modification
Vulnerability report for CVE-2026-102478, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-07
Last updated on: 2026-10-07
Assigner: Octopus Deploy
Description
Description
In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to improper validation of unsafe equivalence in inputs.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Octopus | Deploy | Octopus Server 2023.2.945 |
| Octopus | Deploy | Octopus Server 2026.2.0 |
| Octopus | Deploy | Octopus Server 2026.3.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1289 | The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value. |