In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters.
When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validity to create extra user accounts above the initial number of invited users.