---
id: CVE-2026-102478
title: >-
  In affected versions of Octopus Server, an authenticated user with permission
  to modify roles could bypass the protections preventing access abuse resulting
  in privilege escalation
summary: >-
  In affected versions of Octopus Server, an authenticated user with permission
  to modify roles could bypass the protections preventing access abuse resulting
  in privilege escalation. It was possible for the built-in role to be weakened
  an…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-1289
vendor: Octopus Deploy
product: Octopus Server
affected:
  - octopus_server >= 2023.2.945 < 2026.1.11768
  - octopus_server >= 2026.2.0 < 2026.2.13408
  - octopus_server >= 2026.3.0 < 2026.3.15816
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:31.010'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102478'
references:
  - url: 'https://advisories.octopus.com/post/2026/sa2026-11'
    label: security@octopus.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-07T18:40:08.538496Z'
cvssSource: cna
ingestedAt: '2026-10-07T02:28:07.546Z'
epss: 0.00295
epssPercentile: 0.20329
---

## Overview

In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to improper validation of unsafe equivalence in inputs.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
