GBHackers

Octopus Server Flaw Lets Authenticated Attackers Execute Arbitrary Code


Octopus Deploy has announced a high-severity vulnerability in Octopus Server that could allow authenticated users with project or environment editing permissions to execute arbitrary code within the Octopus Server process.

Tracked as CVE-2026-101169, this issue stems from insecure JSON deserialization and affects multiple Octopus Server releases running on both Linux and Microsoft Windows.

Organizations using vulnerable self-hosted deployments are urged to upgrade immediately, as no workarounds or alternative mitigations are currently available.

Octopus Server Flaw

According to Octopus Deploy’s Security Advisory 2026-10, an attacker must first authenticate to an affected Octopus Server instance and have permissions to edit an environment or project.

The attacker can then supply specially crafted JSON content for an affected object. If Octopus Server deserializes this malicious JSON insecurely, it may execute attacker-controlled code within the Octopus Server process.

This vulnerability could provide an attacker with a significant foothold in a deployment automation environment. Octopus Server is commonly used to coordinate application releases, manage deployment targets, store deployment variables, and integrate with cloud platforms, CI/CD systems, and infrastructure environments.

Depending on the permissions assigned to the server process and its connected deployment resources, successful exploitation could lead to access to sensitive deployment configurations, credentials, automation scripts, or downstream infrastructure.

Octopus stated that version 2026.4.x was only available through Octopus Cloud when it issued the fix. Cloud customers do not need to take action, as hosted instances have already been updated to a patched release.

Octopus Deploy released fixes on September 14, 2026, and publicly disclosed the issue on September 29, 2026. The company recommends upgrading to the latest available release, Octopus Server 2026.3.15863.

For organizations unable to move to the newest release, the following patched versions should be installed within their supported feature branch:

  • Upgrade 2019.4.x through 2025.x deployments to version 2026.1.11781 or later.
  • Upgrade 2026.1.x deployments to version 2026.1.11781 or later.
  • Upgrade 2026.2.x deployments to version 2026.2.13441 or later.
  • Upgrade 2026.3.x deployments to version 2026.3.15829 or later.

Octopus Deploy has stated that it is not aware of any public exploitation or malicious activity involving CVE-2026-101169. The vulnerability was identified during internal testing by Nathan Willoughby at Octopus Deploy.

Administrators should prioritize patching internet-accessible and high-privilege Octopus Server installations, review accounts with Environment and Project editing rights, and monitor server activity for unexpected configuration changes or process executions.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link