Cyber Security News

Octopus Server Flaw Lets Authenticated Attackers Execute Arbitrary Code

Octopus Deploy has announced a high-severity vulnerability in Octopus Server that could allow authenticated users with project or environment editing permissions to execute arbitrary code within the Octopus Server process.

Tracked as CVE-2026-101169, this issue stems from insecure JSON deserialization and affects multiple Octopus Server releases running on both Linux and Microsoft Windows.

Organizations using vulnerable self-hosted deployments are urged to upgrade immediately, as no workarounds or alternative mitigations are currently available.

Octopus Server Flaw

According to Octopus Deploy’s Security Advisory 2026-10, an attacker must first authenticate to an affected Octopus Server instance and have permissions to edit an environment or project.

The attacker can then supply specially crafted JSON content for an affected object. If Octopus Server deserializes this malicious JSON insecurely, it may execute attacker-controlled code within the Octopus Server process.

This vulnerability could provide an attacker with a significant foothold in a deployment automation environment. Octopus Server is commonly used to coordinate application releases, manage deployment targets, store deployment variables, and integrate with cloud platforms, CI/CD systems, and infrastructure environments.

Depending on the permissions assigned to the server process and its connected deployment resources, successful exploitation could lead to access to sensitive deployment configurations, credentials, automation scripts, or downstream infrastructure.

Octopus stated that version 2026.4.x was only available through Octopus Cloud when it issued the fix. Cloud customers do not need to take action, as hosted instances have already been updated to a patched release.

Octopus Deploy released fixes on September 14, 2026, and publicly disclosed the issue on September 29, 2026. The company recommends upgrading to the latest available release, Octopus Server 2026.3.15863.

For organizations unable to move to the newest release, the following patched versions should be installed within their supported feature branch:

  • Upgrade 2019.4.x through 2025.x deployments to version 2026.1.11781 or later.
  • Upgrade 2026.1.x deployments to version 2026.1.11781 or later.
  • Upgrade 2026.2.x deployments to version 2026.2.13441 or later.
  • Upgrade 2026.3.x deployments to version 2026.3.15829 or later.

Octopus Deploy has stated that it is not aware of any public exploitation or malicious activity involving CVE-2026-101169. The vulnerability was identified during internal testing by Nathan Willoughby at Octopus Deploy.

Administrators should prioritize patching internet-accessible and high-privilege Octopus Server installations, review accounts with Environment and Project editing rights, and monitor server activity for unexpected configuration changes or process executions.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

3 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

5 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago