CVE-2026-0704

CRITICAL WAF: High
CVSS 9.1 Published: 2026-02-25
CWE-22

In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.

WAF Coverage Analysis

Path Traversal High WAF Coverage

OWASP: A01:2021 Broken Access Control

930xxx - Local File Inclusion

Affected Software

VendorProductVersion
octopusoctopus_server2023.1.4189 - 2025.3.14715

References

Back to CVE Database