Skip to content
Critical Path Traversal Vulnerability in Octopus Server (CVE-2026-92355)

Critical Path Traversal Vulnerability in Octopus Server (CVE-2026-92355)

First seen 18 Sep 2026, 01:59 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 02:00 UTC
  • CVE-2026-92355 allows file overwriting via path traversal in Octopus Server.
  • Authenticated users can exploit this vulnerability, potentially leading to remote code execution.
  • Immediate action is required to restrict permissions and apply patches.

A critical path traversal vulnerability (CVE-2026-92355) has been identified in affected versions of Octopus Server, allowing authenticated users with permissions to modify non built-in external feeds to overwrite arbitrary files. This flaw could potentially lead to remote code execution depending on system configurations. The CVSS base score assigned to this vulnerability is 8.7, indicating a high severity level. Currently, there is no public proof-of-concept or evidence of active exploitation. Security teams are advised to restrict feed modification permissions and apply available patches promptly. The vulnerability was published on September 16, 2026, and is categorized under CWE-22. Affected systems include all versions of Octopus Server that allow modification of external feeds.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
CVE-2026-92355 published
The vulnerability was disclosed, affecting Octopus Server versions that allow modification of external feeds.
cve.akaoma.com
2026-09-17
CVE-2026-92355 details reported
Feedly reported on the vulnerability, emphasizing the need for immediate patching and permission audits.
Feedly
2026-09-17
CVE-2026-93451 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-17
CVE-2026-93453 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-17
CVE-2026-93450 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-17
CVE-2026-93452 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-18
Vulnerability awareness raised
cve.report reiterated the details of CVE-2026-92355, confirming its critical nature and potential impact.
cve.report

More articles in this cluster (6)

Following this threat?

Track CVE-2026-92355 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed