CVE-2026-8296
Received Received - Intake
Cross-Site Scripting via Artifacts in Octopus Server

Publication date: 2026-06-19

Last updated on: 2026-06-19

Assigner: Octopus Deploy

Description
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-19
Last Modified
2026-06-19
Generated
2026-06-19
AI Q&A
2026-06-19
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
octopus_deploy octopus_server to 2025.4.10678|end_excluding=2026.1.11451|end_excluding=2026.2.13114|start_including=2023.0|start_including=2024.0|start_including=2025.0|start_including=2026.1 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-8296 is a stored Cross-Site Scripting (XSS) vulnerability in Octopus Server. It allows attackers with certain access levels to embed malicious scripts via artifacts in affected versions of the software.

This vulnerability affects all 2023.x, 2024.x, 2025.x (except 2025.4.10678 and later), and 2026.1.x (before 2026.1.11451) and 2026.2.x (before 2026.2.13114) releases of Octopus Server.

The issue was discovered internally by Octopus Deploy's security team and has a medium severity rating with a CVSS score of 5.6.

Impact Analysis

This vulnerability can allow attackers with certain access levels to inject malicious scripts into the Octopus Server via artifacts. These scripts could be executed in the context of users viewing the artifacts, potentially leading to unauthorized actions or data exposure.

Since it is a stored XSS vulnerability, the malicious payload persists and can affect multiple users, increasing the risk of exploitation.

There is no mitigation other than upgrading to fixed versions, so users are urged to update immediately to prevent potential exploitation.

Detection Guidance

There is no specific information provided about detection methods or commands to identify this vulnerability on your network or system.

Mitigation Strategies

No mitigations exist for this vulnerability other than upgrading the affected Octopus Server to a fixed version.

  • Upgrade to Octopus Server version 2025.4.10678 or later.
  • Alternatively, upgrade to version 2026.1.11451 or later.
  • Alternatively, upgrade to version 2026.2.13114 or later, with 2026.2.13115 being the latest recommended version.

Users are urged to upgrade immediately to prevent potential exploitation.

Compliance Impact

The provided information does not specify how CVE-2026-8296 affects compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8296. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart