In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.
References
| Link | Resource |
|---|---|
| https://advisories.octopus.com/post/2026/sa2026-01 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
27 Feb 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-22 |
27 Feb 2026, 03:29
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
| References | () https://advisories.octopus.com/post/2026/sa2026-01 - Vendor Advisory | |
| First Time |
Linux
Octopus octopus Server Microsoft Microsoft windows Octopus Linux linux Kernel |
|
| CPE | cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| CWE | NVD-CWE-noinfo |
25 Feb 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-25 13:16
Updated : 2026-02-27 15:16
NVD link : CVE-2026-0704
Mitre link : CVE-2026-0704
CVE.ORG link : CVE-2026-0704
JSON object : View
Products Affected
linux
- linux_kernel
octopus
- octopus_server
microsoft
- windows
CWE
NVD-CWE-noinfo
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
