CVE-2026-101169 is an insecure deserialization vulnerability in Octopus Server. An authenticated user authorized to edit an Environment or Project object can submit specially crafted JSON content that Octopus Server deserializes insecurely, resulting in arbitrary code execution in the Octopus Server process. The issue affects Octopus Server deployments on Linux and Microsoft Windows, including all 2019.4.x releases, all 2020.x through 2025.x releases, and unpatched releases in the 2026.1 through 2026.4 branches.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity authenticated arbitrary-code-execution vulnerability in Octopus Server caused by insecure deserialization of attacker-controlled JSON associated with Environment and Project objects.
High-severity authenticated arbitrary code execution vulnerability caused by insecure JSON deserialization in Octopus Server Environment and Project object processing. Exploitation requires valid access and permissions to modify one of those objects; code executes in the security context of the Octopus Server process.
An authenticated remote code execution vulnerability in Octopus Server caused by insecure deserialization of specially crafted JSON assigned to Environment or Project objects. Exploitation requires permissions to edit an Environment or Project and results in arbitrary code execution in the Octopus Server process.
An insecure deserialization vulnerability in Octopus Server that allows an authenticated user with permission to edit an Environment or Project to execute arbitrary code in the Octopus Server process through crafted JSON content.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.