Critical severity9.8NVD Advisory· Published Nov 1, 2022· Updated Jun 17, 2026
CVE-2022-2572
CVE-2022-2572
Description
In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1- advisories.octopus.com/post/2022/sa2022-23/nvdVendor Advisory
News mentions
0No linked articles in our index yet.