OCTOPUS Deploy has patched two high-severity vulnerabilities in Octopus Server, including a path-traversal flaw rated CVSS 8.7 that can enable remote code execution. CVE-2026-91778, rated CVSS 7.2, involves incorrect permission validation: users with certain scoped permission sets could execute arbitrary scripts on a worker. CVE-2026-92355 affects the modification of external feeds and could allow an attacker to overwrite arbitrary files, potentially leading to full remote code execution.
The affected software includes all 2019.x through 2025.x releases, as well as 2026.1.x versions before 2026.1.11725 and 2026.2.x versions before 2026.2.13344. The article also lists 2026.3.x versions before 2026.3.13163 as vulnerable. Octopus Deploy’s security team said it was not aware of public announcements or malicious use of CVE-2026-92355, and the report states that neither vulnerability has been confirmed as exploited.
Administrators should upgrade to a fixed release. The article identifies 2026.1.11725 and 2026.2.13344, while listing 2026.3.15816 in its remediation section; its earlier version table instead lists 2026.3.11816, creating an inconsistency that should be checked against the vendor’s advisory. No temporary mitigation is known. Teams are also advised to review audit logs for unauthorised script execution.