TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2026-0704

CRITICAL
9.1

Beschreibung

In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.

CVE Details

CVSS v3.1 Bewertung9.1
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht2/25/2026
Zuletzt geandert2/27/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

linux:linux_kernelmicrosoft:windowsoctopus:octopus_server

Schwachen (CWE)

CWE-22

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.