In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://advisories.octopus.com/post/2026/sa2026-01 |
|
History
Wed, 25 Feb 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows. | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Octopus
Published:
Updated: 2026-02-25T12:22:18.328Z
Reserved: 2026-01-08T01:25:18.708Z
Link: CVE-2026-0704
No data.
Status : Received
Published: 2026-02-25T13:16:04.337
Modified: 2026-02-25T13:16:04.337
Link: CVE-2026-0704
No data.
OpenCVE Enrichment
No data.