{"id":"CVE-2026-92355","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-92355","summary":"In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server,…","details":"In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary files on the server, which in some configurations could lead to remote code execution.","published":"2026-09-16T08:16:40.813","modified":"2026-09-16T19:41:10.423","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://advisories.octopus.com/post/2026/sa2026-09"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T19:41:10.423"}}