Executive brief
Octopus Server is a deployment automation platform used to manage releases and configurations across distributed infrastructure. A flaw in permission validation allows users with limited access to execute arbitrary scripts on worker machines, including the built-in server worker, bypassing authorization controls that should restrict such actions. This could enable unauthorized users to compromise worker machines and potentially gain access to sensitive deployment data and infrastructure.
Technical details
The vulnerability is an authorization bypass in Octopus Server's script execution engine on workers. Users with certain scoped permission sets could execute arbitrary scripts without possessing the required authorisation due to incorrect permission validation logic. The vulnerability affects script execution on workers including the built-in Octopus Server worker, allowing network-accessible authenticated users to escalate privileges and run commands outside their intended scope. No public exploits are known at the time of advisory release. Patches are available for all affected major versions: 2026.1.11725, 2026.2.13344, and 2026.3.15816.
Affected products
- Octopus Deploy Octopus Server All 2019.x, 2020.x, 2021.x, 2022.x, 2023.x, 2024.x, 2025.x; all 2026.1.x before 2026.1.11725; all 2026.2.x before 2026.2.13344; all 2026.3.x before 2026.3.15816
Timeline
- 2026-09-15: disclosed
- 2026-08-20: patched