CVE-2026-101169 PUBLISHED

Assigner: Octopus
Reserved: 28.09.2026 Published: 29.09.2026 Updated: 29.09.2026

In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of this content allows the user to execute arbitrary code in the Octopus Server process.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Octopus Deploy
Product Octopus Server
Versions Default: unaffected
  • affected from 2019.4.1 to 2026.1.11781 (excl.)
  • affected from 2026.2.0 to 2026.2.13441 (excl.)
  • affected from 2026.3.0 to 2026.3.15829 (excl.)

Credits

  • This vulnerability was found by Nathan Willoughby finder

References

Problem Types

  • CWE-502: Deserialization of Untrusted Data CWE