CVE-2026-8296 is a medium-severity vulnerability in Octopus Server that allows for Cross-Site Scripting (XSS) via artifacts with certain access levels. The vulnerability has a CVSS score of 5.6 and was published on June 19, 2026. The affected product is Octopus Server, and the defender exposure question is whether the server has certain access levels that could embed a Cross-Site Scripting Payload via art [truncated]
A medium severity vulnerability, CVE-2026-4881, was found in Octopus Server. The issue arises from incorrect permission checks, allowing any authenticated user to make server-level changes using a specific API endpoint, despite receiving an error message. The vulnerability has a CVSS score of 6 and is classified as MEDIUM.