Unrated severityNVD Advisory· Published Mar 5, 2026· Updated Mar 5, 2026
CVE-2026-3236
CVE-2026-3236
Description
In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token.
Affected products
1- Octopus Deploy/Octopus Serverv5Range: 2023.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.