OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-102478 (CVSS 8.7)

NVD · officialPublished Oct 7, 2026Risk 37/100

In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to improper validation of unsafe equivalence in inputs.

CVSS
8.7
AV:NetworkAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source