In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://advisories.octopus.com/post/2026/sa2026-09 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-16 08:16
Updated : 2026-09-16 08:16
NVD link : CVE-2026-92355
Mitre link : CVE-2026-92355
CVE.ORG link : CVE-2026-92355
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
