CVE-2024-23637Medium· 4.2▾ SunlitOctoPrint Unverified Password Change via Access Control Settings
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to change the password of other admin accounts, including their own, without having to repeat their password.
An attacker who managed to hijack an admin account might use this to lock out actual admins from their OctoPrint instance.
The vulnerability will be patched in version 1.10.0.
OctoPrint administrators are strongly advised to thoroughly vet who has admin access to their installation.
This vulnerability was discovered and responsibly disclosed to OctoPrint by Timothy "TK" Ruppert.
octoprint < 1.10.0rc1Upgrade to a patched release:
octoprint 1.10.0rc1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-23892Medium· 5.9OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication
CVE-2025-48067Medium· 5.4OctoPrint vulnerable to possible file extraction via upload endpoints
CVE-2025-64187MediumOctoPrint vulnerable to XSS in Action Commands Notification and Prompt
CVE-2025-48879Medium· 6.5OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint
CVE-2025-58180High· 8.8OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload
CVE-2022-2822Low· 3.7OctoPrint does not have rate limiting on the login page