CVE-2026-4881
EUVD-2026-3422704.06.2026, 10:16
In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| octopus | octopus_server | 2023.1.4189 ≤ 𝑥 < 2025.4.10545 |
| octopus | octopus_server | 2026.1.675 ≤ 𝑥 < 2026.1.11313 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration