CVE-2026-0704
CVE-2026-0704
In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
Octopus Deploy · Octopus ServerQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →