Junglewise Threat Intelligence

CVE-2026-8296: Octopus Deploy Octopus Server stored XSS in artifacts

CVE-2026-8296 · Severity: info · CVSS 5.6 · Published 2026-06-19

Executive brief

Octopus Server, a platform used for automating software deployments, is affected by a security vulnerability that allows users with specific access levels to inject malicious scripts into system artifacts. If an administrator or another user views these compromised artifacts, the script could execute in their browser, potentially leading to unauthorized actions or data access. Organizations should upgrade to the latest patched versions to prevent this risk.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Octopus Server within the artifacts component. An attacker with high privileges (PR:H) can embed a malicious payload into an artifact. The vulnerability is triggered when another user, typically an administrator, interacts with the affected artifact in their web browser. While the attack requires high privileges and user interaction, it can lead to a high impact on confidentiality (VC:H) within the application session. Patches have been released in versions 2025.4.10678, 2026.1.11451, and 2026.2.13114.

Affected products

  • Octopus Deploy Octopus Server 2023.x, 2024.x, 2025.1.x - 2025.3.x, 2025.4.x before 2025.4.10678, 2026.1.x before 2026.1.11451, 2026.2.x before 2026.2.13114

Timeline

  • 2026-03-19: other: Vulnerability discovered
  • 2026-05-12: patched: Patch release date
  • 2026-06-11: advisory: Internal advisory published
  • 2026-06-19: disclosed: CVE published to NVD

References

Related threats