OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-101169

HIGH · CVSS 8.7 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Octopus Server is vulnerable to insecure deserialization, allowing authenticated users with edit permissions for an Environment or Project to inject malicious JSON content. This can lead to arbitrary code execution within the Octopus Server process, posing a significant security risk. Organizations using Octopus Server should prioritize patching this vulnerability to protect their environments from potential exploitation.

CVE
CVE-2026-101169
Severity
HIGH
CVSS
8.7
EPSS
0.33%

Original NVD Description

In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of this content allows the user to execute arbitrary code in the Octopus Server process.