CVE Database
/

CVE-2026-0704

Back to search

CVE-2026-0704

Published: Feb 25, 2026

Modified: Feb 27, 2026

PUBLISHED

Description

In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.

VendorProductVersions

Octopus Deploy

Octopus Server

affected
2023.0.0 - < 2025.3.14715
affected
2025.4.0 - < 2025.4.10359

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now