CVSS8.8
Severityhigh
WeaknessCWE-269
ExploitedNot in CISA KEV
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.
octopus · codefresh
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.
No stories yet. This page updates automatically when we publish reporting that references CVE-2026-12878.