Octopus Server has disclosed a high-severity security flaw—tracked as CVE-2026-92355—that could let attackers with limited permissions overwrite files or even execute code remotely. The vulnerability stems from a path traversal bug affecting non built-in external feeds. Users granted rights to modify these feeds may exploit this flaw to traverse directories and replace arbitrary files on the server. In certain setups, that can escalate into full remote code execution. The severity is rated high with a CVSS score of 8.7.
The issue impacts multiple versions of Octopus Server on both Linux and Windows platforms. Specifically, versions from the 2024.1.4131 release up to versions before build 2026.1.11725; and in subsequent lines, versions of 2026.2 before 2026.2.13344, and 2026.3 before 2026.3.11816, are all vulnerable.
What’s at stake & who’s affected
Any organization using affected versions of Octopus Server risks unauthorized file manipulation through feeds that aren’t built-in. Even though only users with the ability to modify external feeds are directly exposed, the flaw’s ability to overwrite critical files means attacks could run arbitrary code. The flaw isn’t limited to one OS—it spans across both Windows and Linux environments.
Steps to mitigation and patching
Octopus Deploy has pushed out fixed versions in all affected branches. For 2024 line users, upgrading beyond the designated safe builds eliminates exposure. Users of 2026.2 and 2026.3 branches must also upgrade to at least build 2026.2.13344 and 2026.3.11816 respectively.
Users unsure about whether their setup includes vulnerable external feeds or custom configurations that might widen the attack surface should audit permissions and feed configurations immediately. There’s no known workaround beyond updating to a patched version, so organizations must prioritize this update.
This vulnerability was identified internally by security researcher Nathan Willoughby. There are currently no public reports of the flaw being actively exploited.
Why this matters:Octopus Server is a widely used deployment automation tool, and vulnerabilities like these can compromise supply chains, continuous deployment pipelines, and developer workflows. Attackers gaining even limited file write access can introduce malware, backdoors, or disrupt critical operations.
What to watch: Track Octopus Deploy’s advisories closely—version numbers are key. Ensure both server and external feed configurations are properly locked down. Given the severity and potential for code execution, any hesitation to patch could yield serious consequences for organizations relying on Octopus for CI/CD and deployment orchestration.