CVE-2026-92355

In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-16 08:16

Updated : 2026-09-16 08:16


NVD link : CVE-2026-92355

Mitre link : CVE-2026-92355

CVE.ORG link : CVE-2026-92355


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')