Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://advisories.octopus.com/post/2026/sa2026-08 |
|
Tue, 15 Sep 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the user possessing the required authorisation. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Octopus
Published:
Updated: 2026-09-15T07:08:54.502Z
Reserved: 2026-09-15T01:38:15.839Z
Link: CVE-2026-91778
No data.
Status : Received
Published: 2026-09-15T08:17:07.180
Modified: 2026-09-15T08:17:07.180
Link: CVE-2026-91778
No data.
OpenCVE Enrichment
No data.
-
CWE-863
Incorrect Authorization