
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3236 is an Incorrect Authorization vulnerability in Octopus Server that allows authenticated users to create a new API key from an existing access token, with the resulting API key having a lifetime that exceeds that of the original access token used to generate it. This effectively allows a user to extend their access beyond the intended expiration of their credentials. The vulnerability was published on March 5, 2026, with a patch made available on March 12, 2026. Affected versions include Octopus Server 2023.1.4189 through 2025.3.14761 (exclusive) and 2025.4.51 through 2025.4.10409 (exclusive). It carries a CVSS v3.1 base score of 4.3 (Medium) (Octopus Advisory, Red Hat CVE).
The root cause is classified as CWE-863 (Incorrect Authorization), where the server fails to properly enforce the lifetime constraints of an access token when it is used to mint a new API key. Specifically, the authorization logic does not propagate or enforce the expiration of the originating access token onto the newly created API key, allowing the derived key to outlive its parent credential. Exploitation requires a low-privileged, authenticated network-accessible account and no user interaction. No public proof-of-concept code has been identified at this time (Octopus Advisory, Red Hat CVE).
Successful exploitation allows an authenticated attacker to persist access to an Octopus Server instance beyond the intended expiration of their credentials by generating a long-lived API key from a short-lived access token. This primarily affects integrity (unauthorized credential persistence) with limited confidentiality impact, as the attacker could use the extended API key to continue interacting with the deployment automation platform after their session should have expired. There is no direct availability impact, but persistent unauthorized access to a CI/CD orchestration platform like Octopus Server could facilitate supply chain attacks or unauthorized deployment actions (Octopus Advisory).
No public exploit code or in-the-wild exploitation has been reported for CVE-2026-3236. The EPSS score is approximately 0.038%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated low-privileged account, which limits the attack surface compared to unauthenticated vulnerabilities (Octopus Advisory, Red Hat CVE).
ApiKey created) initiated via an access token, particularly where the new API key's expiration significantly exceeds the access token's expected lifetime./api/users/{userId}/apikeys) from authenticated sessions that should have expired.Octopus Deploy has released patched versions addressing this vulnerability: users on the 2023.x–2025.3.x branch should upgrade to 2025.3.14761 or later, and users on the 2025.4.x branch should upgrade to 2025.4.10409 or later. As a workaround, administrators should audit existing API keys for unexpected lifetimes and revoke any keys that appear to have been created with excessively long expirations. Restricting API key creation permissions to trusted users and monitoring audit logs for anomalous key creation activity is also recommended (Octopus Advisory).
Coverage of CVE-2026-3236 has been limited to automated vulnerability tracking platforms and aggregators. A brief technical summary was published by Infinit Security (Infinit Security). No significant vendor statements beyond the official advisory, notable researcher commentary, or broad media coverage have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."