216.73.216.6

CVE-2026-3237

· Published 17/03/2026 07:16 · Modified 17/03/2026 14:20

Labels: CVE-2026-3237 2026-03-17CVE-2026-3237CWE-285[email protected]

Essential information

Published
17/03/2026 07:16
Modified
17/03/2026 14:20
Author
Creator
CVSS
2.3 LOW (v3) 2.3 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via an API endpoint that had incorrect permission validation. It was not possible to expose the signing keys using this vulnerability.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
octopus / octopus server cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*

References