Vulnerability Description
In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Octopus | Octopus Server | >= 2023.1.4189, < 2025.3.14715 |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://advisories.octopus.com/post/2026/sa2026-01Vendor Advisory
FAQ
What is CVE-2026-0704?
CVE-2026-0704 is a vulnerability with a CVSS score of 9.1 (CRITICAL). In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to ...
How severe is CVE-2026-0704?
CVE-2026-0704 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-0704?
Check the references section above for vendor advisories and patch information. Affected products include: Octopus Octopus Server, Linux Linux Kernel, Microsoft Windows.