CVE-2026-0704
CRITICAL WAF: High
CVSS 9.1
Published: 2026-02-25
CWE-22
In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.
WAF Coverage Analysis
Path Traversal
High WAF Coverage
OWASP: A01:2021 Broken Access Control
930xxx - Local File Inclusion
Affected Software
| Vendor | Product | Version |
|---|---|---|
| octopus | octopus_server | 2023.1.4189 - 2025.3.14715 |
References
- advisories.octopus.com (Vendor Advisory)