{"id":"CVE-2026-12878","title":"In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.","summary":"In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-269"],"vendor":"octopus","product":"codefresh","affected":["codefresh >= 2.0.0, < 2.11.15"],"patched":["codefresh 2.11.15"],"published":"2026-08-25","updated":"2026-09-28","sourceUpdated":"2026-09-28T23:10:00.143","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12878","references":[{"url":"https://advisories.codefresh.io/post/2026/sa2026-01/","label":"security@octopus.com"}],"tags":["nvd"],"ingestedAt":"2026-09-28T23:23:00.545Z","slug":"CVE-2026-12878","body":"## Overview\n\nIn affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.\n\n## Affected\n\n- `codefresh >= 2.0.0, < 2.11.15`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `codefresh 2.11.15`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}