CVE-2026-8296
Received
Received - Intake
Cross-Site Scripting via Artifacts in Octopus Server
Publication date: 2026-06-19
Last updated on: 2026-06-19
Assigner: Octopus Deploy
Description
Description
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| octopus_deploy | octopus_server | to 2025.4.10678|end_excluding=2026.1.11451|end_excluding=2026.2.13114|start_including=2023.0|start_including=2024.0|start_including=2025.0|start_including=2026.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |