In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://advisories.octopus.com/post/2026/sa2026-04 |
|
History
Thu, 04 Jun 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated User Can Perform Server‑Level Changes via API in Octopus Server | |
| Weaknesses | CWE-285 |
Thu, 04 Jun 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error. | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Octopus
Published:
Updated: 2026-06-04T08:49:59.083Z
Reserved: 2026-03-26T07:19:05.417Z
Link: CVE-2026-4881
No data.
Status : Received
Published: 2026-06-04T10:16:39.723
Modified: 2026-06-04T10:16:39.723
Link: CVE-2026-4881
No data.
OpenCVE Enrichment
Updated: 2026-06-04T11:30:12Z
Weaknesses