← Vulnerability feed

Vulnerability record · CVE-2018-5706 · published 16 January 2018

CVE-2018-5706: Octopus deploy improper privilege management vulnerability

Octopus · Octopus Deploy

An issue was discovered in Octopus Deploy before 4.1.9. Any user with user editing permissions can modify teams to give themselves Administer System permissions even if they didn't have them, as demonstrated by use of the RoleEdit or TeamEdit permission.

8.8 CVSS 3.0 High EPSS 1.0% · top 38.6% CWE-269 · Improper privilege management
8.8CVSS 3.0 base score, v2 6.5
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Octopus Deploy before 4.1.9. Any user with user editing permissions can modify teams to give themselves Administer System permissions even if they didn't have them, as demonstrated by use of the RoleEdit or TeamEdit permission.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/OctopusDeploy/Issues/issues/4167 Issue TrackingMitigationThird Party Advisory
https://github.com/OctopusDeploy/Issues/issues/4167 Issue TrackingMitigationThird Party Advisory

Track CVE-2018-5706 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-10678Octopus deploy vulnerabilityIn Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can lever…EPSS 1.0%8.8CVE-2018-4862Octopus deploy improper privilege management vulnerabilityIn Octopus Deploy versions 3.2.11 - 4.1.5 (fixed in 4.1.6), an authenticated user with ProcessEdit permission could reference an Azure account in suc…EPSS 1.1%8.8CVE-2017-17665Octopus deploy missing authorization vulnerabilityIn Octopus Deploy before 4.1.3, the machine update process doesn't check that the user has access to all environments. This allows an access-control …EPSS 1.1%8.1CVE-2019-11632Octopus deploy improper privilege management vulnerabilityIn Octopus Deploy 2019.1.0 through 2019.3.1 and 2019.4.0 through 2019.4.5, an authenticated user with the VariableViewUnscoped or VariableEditUnscope…EPSS 1.2%7.8CVE-2021-26556Octopus deploy untrusted search path vulnerabilityWhen Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL s…EPSS 0.26%7.5CVE-2022-2013Octopus deploy vulnerabilityIn Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users wou…EPSS 0.89%7.5CVE-2020-27155Octopus deploy vulnerabilityAn issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle host to present itself…EPSS 1.3%7.5CVE-2020-25825Octopus deploy vulnerabilityIn Octopus Deploy 3.1.0 to 2020.4.0, certain scripts can reveal sensitive information to the user in the task logs.EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2018-5706), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.