PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35163 OctoPrint CVE debrief

OctoPrint provides a web interface for controlling consumer 3D printers. The vulnerability, CVE-2026-35163, is related to Suppressed Command notification popups using PNotify rendering for printer-controlled payload.command and payload.message values without HTML escaping. This allows an attacker to inject HTML and JavaScript into the notification, disrupting prints, reading information available to the victim including sensitive settings when permitted, or performing actions in the victim's OctoPrint session. The issue is fixed in versions 1.11.8 and 2.0.0rc3. To address the vulnerability, OctoPrint users should prioritize updating to version 1.11.8 or 2.0.0rc3. Evidence limits suggest that defenders verify the vulnerability in their environment and review the official advisory for affected scope and severity. Overall, OctoPrint users and administrators should take a comprehensive approach to addressing this vulnerability and preventing potential exploitation.

Vendor
OctoPrint
Product
OctoPrint
CVSS
MEDIUM 4.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

OctoPrint users and administrators should be aware of this vulnerability and take steps to update their installations to prevent exploitation. Affected operators, platforms, and security teams should review the official advisory and assess their exposure to this vulnerability. Vulnerability management and security teams should prioritize updating to version 1.11.8 or 2.0.0rc3 to address the vulnerability. Additionally, users with sensitive settings or configurations should review their OctoPrint sessions for suspicious activity and consider restricting file uploads to prevent crafted file injection. Monitoring OctoPrint sessions for suspicious activity is also recommended. This vulnerability may impact operators who rely on OctoPrint for 3D printing, as an attacker could disrupt prints, read information available to the victim, or perform actions in the victim's OctoPrint session. Therefore, it is crucial for operators to assess their exposure and take necessary precautions to prevent exploitation. Security teams should also review compensating controls for exposed systems while remediation is scheduled and verified. Asset inventory and monitoring can help identify potential vulnerabilities and detect suspicious activity. Rollback/change windows and source tracking can also aid in mitigating the vulnerability and identifying potential sources of exploitation. Overall, OctoPrint users and administrators should take a comprehensive approach to addressing this vulnerability and preventing potential exploitation. This includes updating to the latest version, reviewing and restricting file uploads, monitoring sessions for suspicious activity, and assessing exposure to the vulnerability. By taking these steps, users can help prevent potential disruption and exploitation of their OctoPrint installations. It is also essential to track exceptions, retest remediated assets, and close the item only after evidence is documented to ensure that the vulnerability is fully addressed. Furthermore, users should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up to ensure that the vulnerability is properly addressed. By A

Technical summary

OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command and payload.message values without HTML escaping. An attacker who convinces a victim to print a crafted file can inject HTML and JavaScript into the notification, disrupt prints, read information available to the victim including sensitive settings when permitted, or perform actions in the victim's OctoPrint session.

Defensive priority

OctoPrint users should prioritize updating to version 1.11.8 or 2.0.0rc3 to address the vulnerability.

Recommended defensive actions

  • Update OctoPrint to version 1.11.8 or 2.0.0rc3
  • Review and restrict file uploads to prevent crafted file injection
  • Monitor OctoPrint sessions for suspicious activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The CVE record indicates that OctoPrint versions prior to 1.11.8 and 2.0.0rc3 are vulnerable to HTML and JavaScript injection via Suppressed Command notification popups. The issue is fixed in versions 1.11.8 and 2.0.0rc3. Evidence limits suggest that defenders verify the vulnerability in their environment and review the official advisory for affected scope and severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T19:17:01.170Z and has not been modified since then.