CVE-2026-3236
EUVD-2026-981705.03.2026, 11:15
In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| octopus | octopus_server | 2023.1.4189 ≤ 𝑥 < 2025.3.14761 |
| octopus | octopus_server | 2025.4.51 ≤ 𝑥 < 2025.4.10409 |
𝑥
= Vulnerable software versions