In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.
References
| Link | Resource |
|---|---|
| https://advisories.octopus.com/post/2026/sa2026-01 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-02-25 13:16
Updated : 2026-02-27 15:16
NVD link : CVE-2026-0704
Mitre link : CVE-2026-0704
CVE.ORG link : CVE-2026-0704
JSON object : View
Products Affected
microsoft
- windows
linux
- linux_kernel
octopus
- octopus_server
CWE
NVD-CWE-noinfo
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
