Arbitrary Script Execution Vulnerability in Octopus Server by Octopus Deploy
CVE-2026-91778
7.2HIGH
What is CVE-2026-91778?
In specific versions of Octopus Server, a vulnerability exists that enables users with particular scoped permission sets to execute arbitrary scripts on worker nodes. This includes the built-in worker of Octopus Server. The flaw arises from improper permission validation during the execution of scripts, allowing unauthorized scripts to run without the appropriate permissions, thereby compromising the security and integrity of the system.
Affected Version(s)
Octopus Server Windows 2019.0.0 < 2026.1.11725
Octopus Server Windows 2026.2.0 < 2026.2.13344
Octopus Server Windows 2026.3.0 < 2026.3.11816
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability was found by Nathan Willoughby
