---
id: CVE-2026-101169
title: >-
  In affected versions of Octopus Server, an authenticated user with permissions
  to edit an Environment or Project can set specifically crafted JSON content
  for the object
summary: >-
  In affected versions of Octopus Server, an authenticated user with permissions
  to edit an Environment or Project can set specifically crafted JSON content
  for the object. Insecure deserialization of this content allows the user to
  execut…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-502
vendor: Octopus Deploy
product: Octopus Server
affected:
  - octopus_server >= 2019.4.1 < 2026.1.11781
  - octopus_server >= 2026.2.0 < 2026.2.13441
  - octopus_server >= 2026.3.0 < 2026.3.15829
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T08:17:19.823'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101169'
references:
  - url: 'https://advisories.octopus.com/post/2026/sa2026-10'
    label: security@octopus.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-29T08:30:07.395Z'
---

## Overview

In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of this content allows the user to execute arbitrary code in the Octopus Server process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
