Threat Advisory

Octopus Server Flaw Lets Authenticated Users Execute Code Through Insecure JSON Deserialization

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability, tracked as CVE-2026-101169 with a CVSS score of 9.0, has been discovered in Octopus Server that could allow authenticated users to execute arbitrary code on affected servers through insecure JSON deserialization. This flaw affects deployments on Linux and Microsoft Windows, specifically all Octopus Server releases from 2019.4.x to 2025.x, as well as several 2026 feature branches including 2026.1.x versions earlier than 2026.1.11781, 2026.2.x versions earlier than 2026.2.13441, 2026.3.x versions earlier than 2026.3.15829, and 2026.4.x versions earlier than 2026.4.1619. The vulnerability exists in the way Octopus Server processes JSON content associated with Environment and Project objects, allowing an authenticated user to submit specially crafted JSON data that can be deserialized by the server, enabling arbitrary code execution within the Octopus Server process. This could have significant business impact in enterprise deployment environments where Octopus Server may have access to sensitive application configuration data and infrastructure targets, enabling a malicious insider or compromised administrator account to run code in the security context of the Octopus Server process.

RECOMMENDATION:

We recommend you to upgrade Octopus Server to version 2026.3.15863.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability, tracked as CVE-2026-101169 with a CVSS score of 9.0, has been discovered in Octopus Server that could allow authenticated users to execute arbitrary code on affected servers through insecure JSON deserialization. This flaw affects deployments on Linux and Microsoft Windows, specifically all Octopus Server releases from 2019.4.x to 2025.x, as well as several 2026 feature branches including 2026.1.x versions earlier than 2026.1.11781, 2026.2.x versions earlier than 2026.2.13441, 2026.3.x versions earlier than 2026.3.15829, and 2026.4.x versions earlier than 2026.4.1619. The vulnerability exists in the way Octopus Server processes JSON content associated with Environment and Project objects, allowing an authenticated user to submit specially crafted JSON data that can be deserialized by the server, enabling arbitrary code execution within the Octopus Server process. This could have significant business impact in enterprise deployment environments where Octopus Server may have access to sensitive application configuration data and infrastructure targets, enabling a malicious insider or compromised administrator account to run code in the security context of the Octopus Server process.

RECOMMENDATION:

We recommend you to upgrade Octopus Server to version 2026.3.15863.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu