Executive brief
Octopus Server is a deployment automation platform used to manage application releases across infrastructure. A vulnerability in certain versions allows sensitive variables—such as passwords, API keys, and database credentials—to be printed in plain-text within deployment variable snapshot files, potentially exposing confidential data to unauthorized users with access to the system.
Technical details
The vulnerability is an information disclosure flaw in Octopus Server's deployment variable snapshot generation. Under certain circumstances, sensitive variables that should be redacted or encrypted are instead recorded in clear-text in the snapshot JSON. The issue affects a broad range of versions from 3.x through 2026.1.x and early 2026.2.x releases. An attacker with local or network access to the deployment snapshot data can retrieve exposed credentials without additional authentication. The vulnerability has been patched in Octopus Server 2026.1.11587, 2026.2.13190, and later versions; customers are urged to upgrade immediately as no workaround exists.
Affected products
- Octopus Deploy Octopus Server 3.2.7-3.x, 4.x, 2018.x, 2019.x, 2020.x, 2021.x, 2022.x, 2023.x, 2024.x, 2025.x, 2026.1.x before 2026.1.11587, 2026.2.x before 2026.2.13190
Timeline
- 2026-05-27: disclosed: Discovery date
- 2026-06-30: patched: Patch release date for versions 2026.1.11587 and 2026.2.13190
- 2026-08-20: advisory: Security Advisory 2026-07 published