6
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Description
In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.
Basic Information
ID
CVE-2026-4881
Source
Octopus
Published
Jun 4, 2026 at 08:49
Affected Product
Vendor
Octopus Deploy
Product
Octopus Server
Version
2023.0.0
Affected Versions
Octopus Deploy Octopus Server 2023.0.0
Octopus Deploy Octopus Server 2025.4.0
Octopus Deploy Octopus Server 2026.1.0
Octopus Deploy Octopus Server 2025.4.0
Octopus Deploy Octopus Server 2026.1.0