Octopus Server

Octopus Deploy · 66 CVEs

CVE-2026-78210
HIGH

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an…

Oct 1, 2026

CVE-2026-101169
HIGH

In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can se…

Sep 29, 2026

CVE-2026-92355
HIGH

In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a pa…

Sep 16, 2026

CVE-2026-91778
HIGH

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a…

Sep 15, 2026

CVE-2026-14163
HIGH

In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed…

Aug 20, 2026

CVE-2026-12702
MEDIUM

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user t…

Jul 24, 2026

CVE-2026-8296
MEDIUM

In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Paylo…

Jun 19, 2026

CVE-2026-4881
MEDIUM

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user bein…

Jun 4, 2026

CVE-2026-3237
LOW

In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change…

Mar 17, 2026

CVE-2026-3236
LOW

In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting…

Mar 5, 2026

CVE-2026-0704
MEDIUM

In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API…

Feb 25, 2026

CVE-2025-0539
MEDIUM

In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests t…

Apr 10, 2025

CVE-2025-0588
MEDIUM

In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all s…

Feb 11, 2025

CVE-2025-0513
LOW

In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could co…

Feb 11, 2025

CVE-2025-0526
LOW

In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API…

Feb 11, 2025

CVE-2025-0525
LOW

In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a tar…

Feb 11, 2025

CVE-2025-0589
MEDIUM

In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible fo…

Feb 11, 2025

CVE-2024-1656
LOW

Affected versions of Octopus Server had a weak content security policy.

Sep 11, 2024

CVE-2024-7998
LOW

In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them usi…

Aug 21, 2024

CVE-2024-6972
MEDIUM

In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed…

Jul 25, 2024

CVE-2024-4811
LOW

In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restr…

Jul 25, 2024

CVE-2024-4456
MEDIUM

In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting paylo…

May 8, 2024

CVE-2024-4226
LOW

It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all us…

Apr 30, 2024

CVE-2023-4509
MEDIUM

It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.

Apr 17, 2024

CVE-2024-2975
HIGH

A race condition was identified through which privilege escalation was possible in certain configurations.

Apr 9, 2024

Showing 1 to 25 of 66 CVEs