CVE-2026-101169: Octopus Deploy Octopus Server
High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.
In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of this content allows the user to execute arbitrary code in the Octopus Server process.
Affected products
- Octopus Deploy Octopus Server: from 2019.4.1, before 2026.1.11781 (fixed in 2026.1.11781); from 2026.2.0, before 2026.2.13441 (fixed in 2026.2.13441); from 2026.3.0, before 2026.3.15829 (fixed in 2026.3.15829)
Published 2026-09-29. Last modified 2026-09-29.