Octopus Server
Octopus Deploy · 66 CVEs
In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an…
Oct 1, 2026
In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can se…
Sep 29, 2026
In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a pa…
Sep 16, 2026
In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a…
Sep 15, 2026
In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed…
Aug 20, 2026
In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user t…
Jul 24, 2026
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Paylo…
Jun 19, 2026
In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user bein…
Jun 4, 2026
In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change…
Mar 17, 2026
In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting…
Mar 5, 2026
In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API…
Feb 25, 2026
In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests t…
Apr 10, 2025
In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all s…
Feb 11, 2025
In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could co…
Feb 11, 2025
In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API…
Feb 11, 2025
In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a tar…
Feb 11, 2025
In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible fo…
Feb 11, 2025
Affected versions of Octopus Server had a weak content security policy.
Sep 11, 2024
In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them usi…
Aug 21, 2024
In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed…
Jul 25, 2024
In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restr…
Jul 25, 2024
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting paylo…
May 8, 2024
It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all us…
Apr 30, 2024
It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.
Apr 17, 2024
A race condition was identified through which privilege escalation was possible in certain configurations.
Apr 9, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-78210 | In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the requ… | HIGH | 0.26% | Oct 1, 2026 |
| CVE-2026-101169 | In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for… | HIGH | 0.33% | Sep 29, 2026 |
| CVE-2026-92355 | In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary… | HIGH | 0.69% | Sep 16, 2026 |
| CVE-2026-91778 | In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server bui… | HIGH | 0.43% | Sep 15, 2026 |
| CVE-2026-14163 | In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in… | HIGH | 0.23% | Aug 20, 2026 |
| CVE-2026-12702 | In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment. | MEDIUM | 0.33% | Jul 24, 2026 |
| CVE-2026-8296 | In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts. | MEDIUM | 0.32% | Jun 19, 2026 |
| CVE-2026-4881 | In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes usin… | MEDIUM | 0.37% | Jun 4, 2026 |
| CVE-2026-3237 | In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocati… | LOW | 0.25% | Mar 17, 2026 |
| CVE-2026-3236 | In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exc… | LOW | 0.26% | Mar 5, 2026 |
| CVE-2026-0704 | In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation w… | MEDIUM | 0.34% | Feb 25, 2026 |
| CVE-2025-0539 | In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allo… | MEDIUM | 0.36% | Apr 10, 2025 |
| CVE-2025-0588 | In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all server responses. By submitting a specifi… | MEDIUM | 0.42% | Feb 11, 2025 |
| CVE-2025-0513 | In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they… | LOW | 0.24% | Feb 11, 2025 |
| CVE-2025-0526 | In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation w… | LOW | 0.35% | Feb 11, 2025 |
| CVE-2025-0525 | In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could provide an adversar… | LOW | 0.38% | Feb 11, 2025 |
| CVE-2025-0589 | In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API… | MEDIUM | 0.37% | Feb 11, 2025 |
| CVE-2024-1656 | Affected versions of Octopus Server had a weak content security policy. | LOW | 0.25% | Sep 11, 2024 |
| CVE-2024-7998 | In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them using the maximum lifespan. | LOW | 0.25% | Aug 21, 2024 |
| CVE-2024-6972 | In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text. | MEDIUM | 0.23% | Jul 25, 2024 |
| CVE-2024-4811 | In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts. | LOW | 0.24% | Jul 25, 2024 |
| CVE-2024-4456 | In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page. | MEDIUM | 0.26% | May 8, 2024 |
| CVE-2024-4226 | It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This fu… | LOW | 0.30% | Apr 30, 2024 |
| CVE-2023-4509 | It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt. | MEDIUM | 0.23% | Apr 17, 2024 |
| CVE-2024-2975 | A race condition was identified through which privilege escalation was possible in certain configurations. | HIGH | 0.39% | Apr 9, 2024 |
Showing 1 to 25 of 66 CVEs