PT-2026-102457 · Unknown · Octopus Server
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Octopus Server (affected versions not specified)
Description
An authenticated user with permissions to edit an Environment or Project can provide specifically crafted JSON content for the object. This leads to insecure deserialization, which allows the user to execute arbitrary code within the Octopus Server process. Insecure deserialization occurs when untrusted data is used to abuse the logic of an application to execute unintended code.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Octopus Server