CVE-2026-102488

In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them.

Credits

This vulnerability was found by Nathan Willoughby

References