PT-2026-51635 · Octoprint · Octoprint

CVE-2026-54134

·

Published

2026-06-23

·

Updated

2026-08-21

CVSS v4.0

7.0

High

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OctoPrint versions prior to 1.11.8 OctoPrint versions 2.0.0rc1 through 2.0.0rc2
Description An issue exists where an attacker with FILE UPLOAD permissions can exfiltrate files from the host that OctoPrint has read access to by moving them into the upload folder for subsequent download. This can lead to the exposure of secrets in the configuration or other system files. Additionally, removing critical runtime files could impact host availability after a server restart. The issue stems from parser differentials between the Tornado upload handler and the Flask web application, allowing reserved internal form fields to be smuggled via query parameters or specific request formats. This causes the application to treat arbitrary host files as new uploads.
Affected API endpoints include:
  • '/api/files/{local|sdcard}'
  • '/api/languages'
  • '/plugin/backup/restore'
  • '/plugin/pluginmanager/upload file'
Recommendations Update OctoPrint to version 1.11.8. Update OctoPrint to version 2.0.0rc3.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54134
GHSA-J4H9-PM27-4RFW
PYSEC-2026-2687

Affected Products

Octoprint