PT-2026-91892 · Unknown · Octopus Server

CVE-2026-91778

·

Published

2026-09-15

·

Updated

2026-09-17

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Octopus Server (affected versions not specified)
Description Incorrect permission validation during script execution allows users with certain scoped permission sets to execute arbitrary scripts on a worker, including the Octopus Server built-in worker, without possessing the required authorization.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91778

Affected Products

Octopus Server