Back to search
CVE-2026-3236
Published: Mar 5, 2026
Modified: Mar 5, 2026
PUBLISHED
Description
In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token.
| Vendor | Product | Versions |
|---|---|---|
Octopus Deploy | Octopus Server | affected 2023.0.0 - < 2025.3.14761affected 2025.4.0 - < 2025.4.10409 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now