In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them.CreditsThis vulnerability was found by Nathan WilloughbyReferenceshttps://advisories.octopus.com/post/2026/sa2026-12