Executive brief
Octopus Server, a platform used for automating software deployments, contains a flaw where certain administrative actions are not properly restricted. An authenticated user with low-level access could make unauthorized server-level changes by interacting with a specific API endpoint. While the system may return an error message to the user, the requested changes are still applied, potentially leading to service disruptions or unauthorized configuration modifications.
Technical details
A broken access control vulnerability exists in Octopus Server due to insufficient permission validation on a specific API endpoint. An authenticated attacker with low privileges can send requests to this endpoint to modify server-level settings. A unique characteristic of this flaw is that the server may return an error response to the client, yet the backend logic still executes the requested change. The vulnerability affects multiple major versions including 2023.x through 2026.1.x. Patches have been released in versions 2025.4.10545 and 2026.1.11313, with a general recommendation to upgrade to 2026.1.11481 or higher.
Affected products
- Octopus Deploy Octopus Server 2023.x, 2024.x, 2025.1.x, 2025.2.x, 2025.3.x, 2025.4.x before 2025.4.10545, 2026.1.x before 2026.1.11313
Timeline
- 2026-03-05: other: Vulnerability discovered
- 2026-03-26: patched: Patch released
- 2026-06-03: advisory: Vendor advisory published
- 2026-06-04: disclosed: NVD publication date