CVE-2026-92355
In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution.
- Published Sep 16, 2026
- CVSS 8.7 high
- 0.7% chance of exploitation in the next 30 days (EPSS)