Skip to content
CVE-2026-92355 - Exploits & Severity

CVE-2026-92355 - Exploits & Severity

Feedly September 17, 2026

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

A path traversal flaw in Octopus Server allows users with permission to modify non built-in external feeds to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution.

An authenticated user with permission to modify non built-in external feeds can exploit path traversal to overwrite arbitrary files on the Octopus Server, potentially achieving remote code execution depending on system configuration.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Restrict feed modification permissions to trusted users only. Review and audit which users have permission to modify non built-in external feeds. Apply the available patch as soon as possible to affected Octopus Server instances.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Feedly found the first article mentioning CVE-2026-92355 . See article

NVD published the first details for CVE-2026-92355

A CVSS base score of 8.7 has been assigned.

GitHub Advisories released a security advisory .

Authorization Bypass (CVSS 8.7): Critical Octopus Server Vulnerabilities Patched

In affected versions of Octopus Server, a user with permission to modify non ...

Be the first to know critical vulnerabilities

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

CWE Weaknesses (1)

Platforms (1)