Arbitrary Script Execution Vulnerability in Octopus Server by Octopus Deploy
CVE-2026-91778

7.2HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-91778?

In specific versions of Octopus Server, a vulnerability exists that enables users with particular scoped permission sets to execute arbitrary scripts on worker nodes. This includes the built-in worker of Octopus Server. The flaw arises from improper permission validation during the execution of scripts, allowing unauthorized scripts to run without the appropriate permissions, thereby compromising the security and integrity of the system.

Affected Version(s)

Octopus Server Windows 2019.0.0 < 2026.1.11725

Octopus Server Windows 2026.2.0 < 2026.2.13344

Octopus Server Windows 2026.3.0 < 2026.3.11816

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability was found by Nathan Willoughby
.