CVE-2021-26556
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.3%
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.
Affected products
Octopus Deploy · Octopus Server