In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://advisories.octopus.com/post/2026/sa2026-07/ |
|
History
Wed, 02 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 21 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Octopus
Octopus octopus Server |
|
| Vendors & Products |
Octopus
Octopus octopus Server |
Thu, 20 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Information Exposure of Sensitive Variables in Octopus Deploy Server Deployment Snapshots |
Thu, 20 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-532 |
Thu, 20 Aug 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text. | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Octopus
Published: 2026-08-20T06:48:07.436Z
Updated: 2026-08-20T15:20:16.958Z
Reserved: 2026-06-30T05:02:49.177Z
Link: CVE-2026-14163
No data.
Status : Analyzed
Published: 2026-08-20T07:16:32.250
Modified: 2026-09-02T00:00:34.117
Link: CVE-2026-14163
No data.