PatchSiren

Octopus Deploy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Octopus Deploy CVE published 2026-08-25

CVE-2026-12878

An authenticated user can utilize an API endpoint to elevate to Admin permissions in affected Codefresh platform versions. This vulnerability, tracked as CVE-2026-12878, allows an authenticated user to leverage a specific API endpoint for privilege escalation. The affected product is the Codefresh platform, with versions prior to 2.11.15 being vulnerable. The vulnerability has a high CVSS score of 8.6, in [truncated]

HIGH Octopus Deploy CVE published 2026-08-20

CVE-2026-14163

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T07:16:32.250Z and has not been modified since then. The CVE-2026-14163 vulnerability in Octopus Server allows sensitive variables to be printed in clear-text in deployment variable snapshots under certain circumstances. This issue affects Octopus Server versions 3.2.7 to 2026.1.11587 and 2026.2.6 [truncated]

MEDIUM Octopus Deploy CVE published 2026-07-24

CVE-2026-12702

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-24T09:16:22.900Z and has not been modified since then. The vulnerability affects Octopus Deploy, allowing an unauthorized user to trigger a deployment due to insufficient checks on project trigger actions. This has a CVSS score of 5.1 and is classified as MEDIUM severity. Octopus Deploy users and ad [truncated]

MEDIUM Octopus Deploy CVE published 2026-06-19

CVE-2026-8296

CVE-2026-8296 is a medium-severity vulnerability in Octopus Server that allows for Cross-Site Scripting (XSS) via artifacts with certain access levels. The vulnerability has a CVSS score of 5.6 and was published on June 19, 2026. The affected product is Octopus Server, and the defender exposure question is whether the server has certain access levels that could embed a Cross-Site Scripting Payload via art [truncated]

MEDIUM Octopus Deploy CVE published 2026-06-04

CVE-2026-4881

A medium severity vulnerability, CVE-2026-4881, was found in Octopus Server. The issue arises from incorrect permission checks, allowing any authenticated user to make server-level changes using a specific API endpoint, despite receiving an error message. The vulnerability has a CVSS score of 6 and is classified as MEDIUM.