CVE Database
/

CVE-2026-3236

Back to search

CVE-2026-3236

Published: Mar 5, 2026

Modified: Mar 5, 2026

PUBLISHED

Description

In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token.

VendorProductVersions

Octopus Deploy

Octopus Server

affected
2023.0.0 - < 2025.3.14761
affected
2025.4.0 - < 2025.4.10409

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now