
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-14163 is a sensitive information disclosure vulnerability in Octopus Server (by Octopus Deploy) where, under certain circumstances, sensitive variables can be printed in clear-text within the deployment variable snapshot. It affects Octopus Server versions from 3.2.6 up to (but not including) 2026.1.11587, and versions from 2026.2.61 up to (but not including) 2026.2.13190. The vulnerability was published on August 20, 2026, with a patch made available the same day. It carries a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory, Octopus Advisory).
The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File / Output), where the application fails to properly mask or redact sensitive deployment variables before including them in the deployment variable snapshot. An authenticated attacker with low privileges can access the deployment variable snapshot through the Octopus Server interface and read sensitive variables — such as credentials, API keys, or secrets — in clear-text that should have been protected. No special attack requirements or user interaction are needed beyond having a valid low-privileged account (GitHub Advisory, Octopus Advisory).
Successful exploitation allows an authenticated user with low privileges to view sensitive variables — including credentials, tokens, and secrets — in clear-text from deployment variable snapshots. This constitutes a high-confidentiality impact, as exposed secrets could be leveraged for lateral movement, privilege escalation, or unauthorized access to downstream systems and services integrated with Octopus Deploy. There is no integrity or availability impact associated with this vulnerability (GitHub Advisory, Octopus Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment confirms no known exploitation. The EPSS score is approximately 0.0023 (0.23%), indicating a low probability of exploitation in the near term. Exploitation is not automatable and requires an authenticated attacker (GitHub Advisory, Octopus Advisory).
/api/deployments/{id}/variables) from unexpected source IPs or user accounts.Octopus Deploy has released patched versions: 2026.1.11587 (for the 2026.1.x branch) and 2026.2.13190 (for the 2026.2.x branch). Organizations should upgrade to these versions immediately. As interim measures, administrators should review existing deployment variable snapshots for any exposed sensitive data and rotate all potentially affected credentials, API keys, and secrets. Access controls should be tightened to restrict who can view deployment variable snapshots until patching is complete (Octopus Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."