In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://advisories.octopus.com/post/2026/sa2026-02 |
|
History
Thu, 05 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Octopus
Published:
Updated: 2026-03-05T14:17:07.392Z
Reserved: 2026-02-26T00:25:55.210Z
Link: CVE-2026-3236
No data.
Status : Received
Published: 2026-03-05T11:15:54.400
Modified: 2026-03-05T11:15:54.400
Link: CVE-2026-3236
No data.
OpenCVE Enrichment
No data.
Weaknesses