---
id: CVE-2026-12878
title: >-
  In affected versions of the Codefresh platform an authenticated user can
  utilize an API endpoint to elevate to Admin permissions.
summary: >-
  In affected versions of the Codefresh platform an authenticated user can
  utilize an API endpoint to elevate to Admin permissions.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: octopus
product: codefresh
affected:
  - 'codefresh >= 2.0.0, < 2.11.15'
patched:
  - codefresh 2.11.15
published: '2026-08-25'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T23:10:00.143'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12878'
references:
  - url: 'https://advisories.codefresh.io/post/2026/sa2026-01/'
    label: security@octopus.com
tags:
  - nvd
ingestedAt: '2026-09-28T23:23:00.545Z'
---

## Overview

In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.

## Affected

- `codefresh >= 2.0.0, < 2.11.15`

## Remediation

Upgrade past the affected range:

- `codefresh 2.11.15`
