CVE-2026-3237 affects Octopus Server, allowing a low-privileged user to manipulate API requests to alter signing key expiration and revocation timeframes due to incorrect permission validation. This vulnerability, rated with a CVSS 4.0 score of 2.3 (LOW), has a network attack vector and low attack complexity, impacting the integrity of key management settings without exposing the signing keys themselves. There is no evidence of active exploitation, no public exploit code available, and minimal community attention or media coverage for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2023.0.0, < 2025.3.14731CPE match | cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* | ||
>= 2025.4.0, < 2025.4.10359CPE match | cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* | ||
>= 2026.1.0, < 2026.1.5571CPE match | cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* | ||
< 2025.3.14731CPE matchmatch criteria | cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* | ||
>= 2025.4.51, < 2025.4.10359CPE matchmatch criteria | cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.