CVE-2026-102488EPSS p9.9%

CVE-2026-102488CVE-2026-102488

Description

In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them.

Scoring

EPSS0.21% probability of exploitation · percentile 9.9% · 2026-10-10T12:00:23Z
Last modified2026-10-08
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.