CVE-2026-8296 Details
Description
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.
A stored cross-site scripting vulnerability has been identified in Octopus Server. Affected versions allow users with certain access levels to embed a cross-site scripting payload within artifacts. This vulnerability is present in all versions of Octopus Server from 2023.x, 2024.x, 2025.1.x, 2025.2.x, 2025.3.x, 2025.4.x prior to 2025.4.10678, 2026.1.x prior to 2026.1.11451, and 2026.2.x prior to 2026.2.13114.
Users are advised to upgrade to Octopus Server versions 2025.4.10678, 2026.1.11451, or 2026.2.13114. The latest versions can be downloaded from the Octopus Deploy website, and previous versions are available from the Octopus Deploy previous versions page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 19, 2026CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://advisories.octopus.com/post/2026/sa2026-05 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Octopus Server | ~2023 ~2024 ~2025.1 ~2025.2 ~2025.3 ~2025.4 ~2026.1 ~2026.2 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | New CVE Received | [email protected] |
Volerion