CVE-2026-3237 Details
Description
In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via an API endpoint that had incorrect permission validation. It was not possible to expose the signing keys using this vulnerability.
A vulnerability exists in Octopus Server that allows low-privileged users to alter the expiration and revocation time frames of signing keys through an API endpoint with inadequate permission validation. This issue is present in all versions of Octopus Server from 2023.x, 2024.x, 2025.1.x, 2025.2.x, 2025.3.x versions prior to 2025.3.14731, all 2025.4.x versions prior to 2025.4.10359, and all 2026.1.x versions prior to 2026.1.5571. While the vulnerability enables modification of signing key settings, it does not allow for exposure of the signing keys themselves.
Users are advised to upgrade to Octopus Server version 2026.1.11242 or, if on an earlier 2026.1.x version, to version 2026.1.5571 or greater. For those on Octopus Server versions 2023.x, 2024.x, 2025.1.x, 2025.2.x, or 2025.4.x, the recommended upgrade paths are to version 2025.3.14731 or greater or 2025.4.10359 or greater, depending on their current version. Customers on Octopus Cloud do not need to take any action.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://advisories.octopus.com/post/2026/sa2026-03 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| octopus octopus server | < 2025.3.14731 >= 2025.4.51, < 2025.4.10359 >= 2026.1.675, < 2026.1.5571 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2026 | Initial Analysis | [email protected] |
| Mar 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | New CVE Received | [email protected] |