CVE-2026-3236

EUVD-2026-9817
In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
octopusoctopus_server
2023.1.4189 ≤
𝑥
< 2025.3.14761
octopusoctopus_server
2025.4.51 ≤
𝑥
< 2025.4.10409
𝑥
= Vulnerable software versions