Executive brief
Octopus Server is a continuous deployment platform used to automate software releases across infrastructure. A user with feed management permissions could exploit a path traversal vulnerability to overwrite arbitrary files on the server, potentially leading to unauthorized code execution and complete system compromise in some configurations.
Technical details
The vulnerability is a path traversal flaw (CWE-22) in Octopus Server's non built-in external feed handling logic. A user with permission to modify external feeds can craft a malicious feed path that bypasses directory restrictions and overwrites arbitrary files on the server. The attack requires valid user credentials with feed modification privileges. In environments where Octopus Server runs with elevated privileges or where writable locations contain executable code, this can escalate to remote code execution. Patches are available in versions 2026.1.11725, 2026.2.13344, and 2026.3.15816 or later.
Affected products
- Octopus Deploy Octopus Server 2024.1.x after 2024.1.4131, 2024.2.x, 2024.3.x, 2024.4.x, all 2025.x, 2026.1.x before 2026.1.11725, 2026.2.x before 2026.2.13344, 2026.3.x before 2026.3.15816
Timeline
- 2026-08-16: disclosed: Discovery date during internal testing
- 2026-08-20: patched: Patch release date
- 2026-09-16: advisory: Public advisory released