SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-91778

HIGH · CVSS 7.2 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Octopus Server is vulnerable due to improper permission validation, allowing users with specific scoped permissions to execute arbitrary scripts on a worker, including the built-in worker. This flaw could lead to unauthorized access and execution of potentially harmful scripts, posing significant security risks. Organizations using Octopus Server should prioritize patching this vulnerability to mitigate the threat of unauthorized script execution.

CVE
CVE-2026-91778
Severity
HIGH
CVSS
7.2
EPSS
0.26%

Original NVD Description

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the user possessing the required authorisation.