← Back to home
wid-sec-w-2026-0742  ·  Published 2026-03-16  ·  View on BSI CERT-Bund ↗

Octopus Deploy: Vulnerability allows Manipulation from Dateien

CVSS 2.3 LOW

Risk Summary

In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via an API endpoint that had incorrect permission validation. It was not possible to expose the signing keys using this vulnerability.

CVEs (1)

Affected Vendors

Octopus Deploy

Affected Products (8)

Octopus Deploy · Octopus Deploy <2026.1.11242
Octopus Deploy · Octopus Deploy 2026.1.11242
Octopus Deploy · Octopus Deploy <2025.3.14731
Octopus Deploy · Octopus Deploy 2025.3.14731
Octopus Deploy · Octopus Deploy <2025.4.10359
Octopus Deploy · Octopus Deploy 2025.4.10359
Octopus Deploy · Octopus Deploy <2026.1.5571
Octopus Deploy · Octopus Deploy 2026.1.5571

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more