In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of this content allows the user to execute arbitrary code in the Octopus Server process.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://advisories.octopus.com/post/2026/sa2026-10 |
|
History
Tue, 29 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Insecure Deserialization Enables Arbitrary Code Execution in Octopus Server |
Tue, 29 Sep 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of this content allows the user to execute arbitrary code in the Octopus Server process. | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Octopus
Published:
Updated: 2026-09-29T07:49:29.618Z
Reserved: 2026-09-28T09:09:50.229Z
Link: CVE-2026-101169
No data.
Status : Received
Published: 2026-09-29T08:17:19.823
Modified: 2026-09-29T08:17:19.823
Link: CVE-2026-101169
No data.
OpenCVE Enrichment
Updated: 2026-09-29T10:00:16Z
Weaknesses