CVE-2026-92355: Path Traversal
Published Sep 16, 2026
·Updated
In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution.
Affected Software
1 affected component
Octopus Deploy Octopus Server
Event History
Sep 16, 2026
CVE Published
via MITRE·07:29 AM
Data Sourced
via MITRE·07:29 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated user needs permission to modify non built-in external feeds. The issue is therefore relevant where that permission is granted to users who should not be able to write arbitrary server files.
2
What is the likely impact if exploitation succeeds?
The attacker could overwrite arbitrary files on the Octopus Server through path traversal. In some configurations, this could lead to remote code execution.