CVE-2026-101169
Received Received - Intake

Authenticated Code Execution in Octopus Server via Insecure Deserialization

Vulnerability report for CVE-2026-101169, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Octopus Deploy

Description

In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of this content allows the user to execute arbitrary code in the Octopus Server process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
octopus_deploy octopus_server From 2019.4.0 (inc) to 2026.4.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Octopus Server allows an authenticated user with permissions to edit an Environment or Project to inject specially crafted JSON content. When deserialized, this content can execute arbitrary code in the Octopus Server process, potentially compromising the entire server.

Detection Guidance

To detect this vulnerability, check the version of your Octopus Server. Affected versions are 2019.4.x through 2026.4.x (excluding patched versions). Run commands like 'octopus.server version' or check the server logs for version information.

Impact Analysis

An attacker with valid credentials could exploit this to take full control of the Octopus Server, leading to unauthorized access, data breaches, or disruption of deployment processes. This could affect all projects and environments managed by the server.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially exposing sensitive data. This may violate compliance requirements like GDPR (data protection) or HIPAA (health information security), resulting in legal penalties or loss of certification.

Mitigation Strategies

Upgrade to version 2026.3.15829 or higher immediately. Octopus Cloud users are already protected. For on-premises or self-hosted versions, apply the latest patch or upgrade to 2026.3.15863 as there is no known mitigation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101169. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart