5.6
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.
Basic Information
ID
CVE-2026-8296
Source
Octopus
Published
Jun 19, 2026 at 09:23
Affected Product
Vendor
Octopus Deploy
Product
Octopus Server
Version
2023.0.0
Affected Versions
Octopus Deploy Octopus Server 2023.0.0
Octopus Deploy Octopus Server 2026.1.0
Octopus Deploy Octopus Server 2026.2.0
Octopus Deploy Octopus Server 2026.1.0
Octopus Deploy Octopus Server 2026.2.0