Octopus Server Flaw Lets Authenticated Users Execute Code Through Insecure JSON Deserialization

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Octopus Deploy has disclosed a high-severity vulnerability in Octopus Server that could allow authenticated users to execute arbitrary code on affected servers through insecure JSON deserialization.

Tracked as CVE-2026-101169, the flaw affects Octopus Server deployments on Linux and Microsoft Windows. The company released Security Advisory 2026-10 on September 29, 2026, and urged customers to upgrade immediately because no mitigation is available.

The issue was discovered during internal testing by Nathan Willoughby of Octopus Deploy. It was identified on September 4, 2026, while patches were released on September 14, 2026.

The vulnerability exists in the way Octopus Server processes JSON content associated with Environment and Project objects. An authenticated user with permission to edit either of these objects can submit specially crafted JSON data.

When Octopus Server deserializes that attacker-controlled content, the insecure deserialization issue can be abused to execute arbitrary code within the Octopus Server process.

This means the attacker must already have valid access to the Octopus Server instance and enough privileges to modify an Environment or Project.

Octopus Server Flaw

However, the impact can still be significant in enterprise deployment environments, where Octopus Server may have access to deployment credentials, automation workflows, infrastructure targets, and sensitive application configuration data.

Successful exploitation could enable a malicious insider, compromised administrator account, or attacker with delegated project permissions to run code in the security context of the Octopus Server process.

The final impact depends on the privileges assigned to that process and the server’s access to connected deployment infrastructure. The vulnerability affects all Octopus Server 2019.4.x releases, all 2020.x through 2025.x releases, and several 2026 feature branches.

Affected releases include 2026.1.x versions earlier than 2026.1.11781, 2026.2.x versions earlier than 2026.2.13441, 2026.3.x versions earlier than 2026.3.15829, and 2026.4.x versions earlier than 2026.4.1619.

Octopus Deploy stated that customers running Octopus Server version 2026.3.15829 or later are not affected. The latest recommended release is version 2026.3.15863.

The 2026.4.x release line was only available to Octopus Cloud when the fix was issued. Octopus Cloud customers do not need to take action because the company has already updated all cloud instances to patched versions.

Organizations should upgrade Octopus Server to the latest available version as soon as possible. Customers unable to move to the latest build should install a fixed release appropriate to their feature branch.

For legacy versions from 2019.4.x through 2025.x, Octopus Deploy recommends upgrading to version 2026.1.11781 or later. Customers using the 2026.2 branch should install version 2026.2.13441 or later, while 2026.3 users should upgrade to version 2026.3.15829 or later.

Octopus Deploy has assigned the vulnerability a high severity rating. The company said it is not aware of public exploitation or malicious use of CVE-2026-101169 at the time of disclosure.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Octopus Server Flaw Lets Authenticated Users Execute Code Through Insecure JSON Deserialization appeared first on Cyber Security News.