TL;DR
Octopus Deploy has fixed a high-severity Octopus Server vulnerability, CVE-2026-101169. An authenticated user who can edit an Environment or Project can run arbitrary code in the server process. Fixed builds shipped on September 14, 2026.
- CVE: CVE-2026-101169
- CVSS: 8.7 (High · CVSSv4)
- Product: Octopus Deploy Octopus Server
- Affected: 2019.4.1, 2026.2.0, 2026.3.0
- Status: No confirmed exploitation yet
- Patched in: 2026.1.11781, 2026.2.13441, 2026.3.15829
- Action: Update to 2026.1.11781, 2026.2.13441, 2026.3.15829 now
Tired of noisy CVE feeds? Set your own EPSS/CVSS alert threshold.
Try free for 14 daysWhy This Octopus Server Vulnerability Matters
Octopus Server drives deployments for many engineering teams. It holds release pipelines, deployment targets, and often cloud and infrastructure credentials. Code execution on that server can give an attacker a path into every environment it deploys to.
The bar for attack is also lower than full admin. Edit rights on a single Environment or Project are enough.
How the Attack Works
The flaw is an insecure deserialization issue, tracked as CWE-502. According to the advisory, “An authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object.” The server then deserializes that content without enough checks. As Octopus puts it, “Insecure deserialization of this content allows the user to execute arbitrary code in the Octopus Server process.”
Affected Versions
The Octopus Server vulnerability affects a wide span of releases on both Linux and Windows:
- All 2019.4.x through 2025.x versions
- 2026.1.x before 2026.1.11781
- 2026.2.x before 2026.2.13441
- 2026.3.x before 2026.3.15829
- 2026.4.x before 2026.4.1619 (Octopus Cloud only)
The vendor states that it “is not aware of any public announcements or malicious use of the vulnerability.” No public proof-of-concept has been confirmed.
Patch and Mitigation Steps
Octopus Cloud customers need to do nothing, since all instances are already patched. Self-hosted users should upgrade to 2026.3.15863, the latest release. If that is not possible, move to 2026.1.11781, 2026.2.13441, or 2026.3.15829 or later. Anyone on 2025.x or older should go to 2026.1.11781 at minimum.
There is no workaround. The Octopus Deploy security advisory SA2026-10 warns: “There is no known mitigation for CVE-2026-101169, it is important to upgrade to a fixed version as soon as possible.” Until you patch, review who holds Environment and Project edit permissions.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!