VulnSea

octopus_server vulnerabilities

CVEs whose affected-version data names the octopus_server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-92355High· 8.7
1w ago

In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code e…

In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code e…

TwilightOctopus Deploy · Octopus ServerEPSS 0.68%via NVD
CVE-2026-91778High· 7.2
1w ago

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker)

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would a…

TwilightOctopus Deploy · Octopus ServerEPSS 0.26%via NVD
CVE-2026-4881Medium· 6.5
3mo ago

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.

Sunlitoctopus · octopus_serverEPSS 0.21%via NVD
octopus_server vulnerabilities (CVEs) · VulnSea