securityonline.info 29 Sept 2026, 09:44 UTC

Octopus Server Flaw Enables Code Execution Through Crafted JSON

Octopus Server Flaw Enables Code Execution Through Crafted JSON
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

OCTOPUS Deploy has disclosed a high-severity vulnerability in Octopus Server, CVE-2026-101169, which permits remote code execution via insecure deserialization. The issue requires an authenticated user with permissions to edit an Environment or Project to craft JSON content that is deserialized by the server without adequate validation.

The vendor states that the vulnerability could enable arbitrary code execution in the Octopus Server process, though there is no confirmed exploitation reported at the time of the advisory. The CVSS score is 8.7 (High, CVSSv4).

Affected releases cover a broad range, spanning all 2019.4.x through 2025.x versions, plus 2026.1.x before 2026.1.11781, 2026.2.x before 2026.2.13441, 2026.3.x before 2026.3.15829, and 2026.4.x before 2026.4.1619 (Octopus Cloud only). Patches have been released: self-hosted users should upgrade to 2026.3.15829 or later, with recommended minimums including 2026.1.11781, 2026.2.13441, or 2026.3.15829; Octopus Cloud instances are already patched.

The vendor’s advisory SA2026-10 notes there is no known mitigation, emphasising the importance of restricting Environment and Project edit permissions until patching. Evidence of active exploitation had not been observed publicly at the time of reporting.

View full article

Article by CyberSIXT