VYPR
Unrated severityNVD Advisory· Published Mar 5, 2026· Updated Mar 5, 2026

CVE-2026-3236

CVE-2026-3236

Description

In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token.

Affected products

1
  • Octopus Deploy/Octopus Serverv5
    Range: 2023.0.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.