Octopus

Server

32 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 08.10.2026 01:38:57
  • Zuletzt bearbeitet 08.10.2026 20:49:23

In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them.

  • EPSS 0.3%
  • Veröffentlicht 07.10.2026 01:17:54
  • Zuletzt bearbeitet 07.10.2026 19:17:31

In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacke...

  • EPSS 0.26%
  • Veröffentlicht 01.10.2026 04:36:23
  • Zuletzt bearbeitet 01.10.2026 16:17:59

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization.

Medienbericht
  • EPSS 0.33%
  • Veröffentlicht 29.09.2026 08:17:19
  • Zuletzt bearbeitet 29.09.2026 21:27:41

In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of this content allows the user to execute arbitrary c...

  • EPSS 0.68%
  • Veröffentlicht 16.09.2026 07:29:27
  • Zuletzt bearbeitet 16.09.2026 19:41:10

In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution.

  • EPSS 0.26%
  • Veröffentlicht 15.09.2026 07:05:53
  • Zuletzt bearbeitet 16.09.2026 19:41:10

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the scri...

  • EPSS 0.23%
  • Veröffentlicht 20.08.2026 06:48:07
  • Zuletzt bearbeitet 02.09.2026 00:00:34

In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text.

  • EPSS 0.19%
  • Veröffentlicht 24.07.2026 09:16:22
  • Zuletzt bearbeitet 17.08.2026 19:09:30

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.

  • EPSS 0.32%
  • Veröffentlicht 19.06.2026 09:23:28
  • Zuletzt bearbeitet 22.06.2026 20:44:48

In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.

  • EPSS 0.21%
  • Veröffentlicht 04.06.2026 08:49:59
  • Zuletzt bearbeitet 22.07.2026 20:10:00

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.