CVE-2026-102478
EUVD-2026-9415407.10.2026, 02:16
In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to improper validation of unsafe equivalence in inputs.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Vulnerability Media Exposure