Ad

CVE-2026-0704

MEDIUM CVSS 4.0: 5.9 EPSS 0.08%
Updated Feb 27, 2026
Octopus
Parameter Value
CVSS 5.9 (MEDIUM)
Affected Versions 2023.1.4189 — 2025.3.14715
Fixed In 2025.3.14715
Vendor Octopus
Public PoC No

In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products 3

Configuration From (including) Up to (excluding)
Octopus Octopus_Server
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*
2023.1.4189 2025.3.14715
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Microsoft Windows
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*