Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
A path traversal flaw in Octopus Server allows users with permission to modify non built-in external feeds to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution.
An authenticated user with permission to modify non built-in external feeds can exploit path traversal to overwrite arbitrary files on the Octopus Server, potentially achieving remote code execution depending on system configuration.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Restrict feed modification permissions to trusted users only. Review and audit which users have permission to modify non built-in external feeds. Apply the available patch as soon as possible to affected Octopus Server instances.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Feedly found the first article mentioning CVE-2026-92355 . See article
NVD published the first details for CVE-2026-92355
A CVSS base score of 8.7 has been assigned.
GitHub Advisories released a security advisory .
Authorization Bypass (CVSS 8.7): Critical Octopus Server Vulnerabilities Patched
In affected versions of Octopus Server, a user with permission to modify non ...
Be the first to know critical vulnerabilities
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
