TL;DR
Octopus Deploy addressed two high-severity Octopus Server vulnerabilities in its continuous delivery platform. These defects permit remote code execution and unauthorized script deployment. Consequently, system administrators must upgrade their server instances to the latest fixed versions to prevent potential system compromises.
- Product: Octopus Deploy Octopus Server
- Vulnerabilities: 2 flaws (CVE-2026-91778, CVE-2026-92355)
- Highest severity: 8.7 (High · CVSSv4)
- Worst impact: In affected versions of Octopus Server, a user with permission to modify non built-in external...
- Status: No confirmed exploitation yet; patches available
- Action: Update to 2026.1.11725, 2026.2.13344, 2026.3.11816 now
| CVE | CVSS (CVSSv4) | Fixed in | Status |
|---|---|---|---|
| CVE-2026-92355 | 8.7 | 2026.1.11725, 2026.2.13344, 2026.3.11816 | Not exploited |
| CVE-2026-91778 | 7.2 | 2026.1.11725, 2026.2.13344, 2026.3.11816 | Not exploited |
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy This Matters
Sourced industry estimates indicate that thousands of enterprise development teams use Octopus Deploy for their continuous delivery pipelines. Therefore, these software flaws present a massive risk to corporate software supply chains. If attackers compromise a central deployment server, they can distribute malware to internal production environments.
How the Attacks Work
Specifically, the first defect, CVE-2026-91778 (CVSS 7.2), involves incorrect permission validation. The advisory states, “Users with certain scoped permission sets could execute arbitrary scripts on a worker.” Because the system fails to validate permissions properly, attackers can bypass authorization controls and run unauthorized commands.
Meanwhile, the second flaw, CVE-2026-92355 (CVSS 8.7), occurs when modifying external feeds. A path traversal weakness allows an attacker to overwrite arbitrary files on the system. As a result, this file manipulation can quickly lead to full remote code execution. However, the vendor confirmed that no active in-the-wild exploitation exists. They stated that the security team “is not aware of any public announcements or malicious use of the vulnerability.”
Affected Versions
These Octopus Server vulnerabilities affect a broad range of installations. Affected branches include all 2019.x through 2025.x versions. Additionally, versions 2026.1.x prior to 2026.1.11725, 2026.2.x prior to 2026.2.13344, and 2026.3.x prior to 2026.3.13163 remain vulnerable.
Patch and Mitigation Steps
Administrators must update their deployments as soon as possible. The developers released versions 2026.1.11725, 2026.2.13344, and 2026.3.15816 to resolve these flaws. There are no known temporary mitigations. Finally, upgrading to a fixed release is the only secure solution. Security teams should also review audit logs for unauthorized script executions to ensure their environments remain secure.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!