CVE-2026-8296: Octopus Deploy Octopus Server

Medium severity, CVSS 5.6. EPSS: 0.3% chance of exploitation in the next 30 days.

In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.

Affected products

  • Octopus Deploy Octopus Server: from 2023.0.0, before 2025.4.10678 (fixed in 2025.4.10678); from 2026.1.0, before 2026.1.11451 (fixed in 2026.1.11451); from 2026.2.0, before 2026.2.13114 (fixed in 2026.2.13114)

Published 2026-06-19. Last modified 2026-06-22.