CVE-2026-92355
Received
Received - Intake
Path Traversal in Octopus Server Leading to RCE
Vulnerability report for CVE-2026-92355, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-16
Last updated on: 2026-09-16
Assigner: Octopus Deploy
Description
Description
In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| octopus_deploy | octopus_server | * |
| octopus | server | 2024.1.* |
| octopus | server | 2024.2.* |
| octopus | server | 2024.3.* |
| octopus | server | 2024.4.* |
| octopus | server | 2025.* |
| octopus | server | to 2026.1.11725 (exc) |
| octopus | server | to 2026.2.13344 (exc) |
| octopus | server | to 2026.3.13163 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-22 | The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. |