CVE-2026-101169 Octopus Server 不安全反序列化漏洞
影响认证用户可远程执行任意代码
AI 研判
Octopus Server 受影响版本中存在不安全反序列化漏洞。拥有编辑环境或项目权限的已认证用户可提交特制 JSON 内容,触发反序列化并在服务器进程中执行任意代码。
影响范围
Octopus Server
Octopus Server 受影响版本,具体版本范围暂无公开信息,建议以官方公告为准。
漏洞详情
漏洞类型为不安全反序列化。成因是服务端对用户提交的 JSON 内容进行反序列化时未做安全校验,攻击者可构造恶意序列化数据。利用方式为具有环境或项目编辑权限的用户提交特制 JSON,从而在 Octopus Server 进程中执行任意代码。
利用条件与风险
利用前提是攻击者已通过认证并拥有编辑环境或项目的权限,属于权限提升/横向利用场景,实战风险较高。
修复建议
官方修复方案暂无公开信息,建议关注 Octopus 官方安全公告并及时升级;临时缓解措施为限制可编辑环境或项目的用户权限并加强审计。
原始情报
In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of this content allows the user to execute arbitrary code in the Octopus Server process.