AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-3237

MEDIUM · CVSS 4.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-03-17 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.3. See the original NVD description below for full technical details.

CVE
CVE-2026-3237
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%

Original NVD Description

In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via an API endpoint that had incorrect permission validation. It was not possible to expose the signing keys using this vulnerability.

Related CVEs

Other vulnerabilities affecting the same vendor(s)