CVE-2026-92355: Octopus Deploy Octopus Server

High severity, CVSS 8.7. EPSS: 0.7% chance of exploitation in the next 30 days.

In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution.

Affected products

  • Octopus Deploy Octopus Server: from 2024.1.4131, before 2026.1.11725 (fixed in 2026.1.11725); from 2026.2.0, before 2026.2.13344 (fixed in 2026.2.13344); from 2026.3.0, before 2026.3.11816 (fixed in 2026.3.11816)

Published 2026-09-16. Last modified 2026-09-16.