In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://advisories.octopus.com/post/2026/sa2026-09 |
|
History
Wed, 16 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution. | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Octopus
Published:
Updated: 2026-09-16T07:29:27.076Z
Reserved: 2026-09-16T04:58:33.621Z
Link: CVE-2026-92355
No data.
Status : Received
Published: 2026-09-16T08:16:40.813
Modified: 2026-09-16T08:16:40.813
Link: CVE-2026-92355
No data.
OpenCVE Enrichment
No data.
Weaknesses