Arbitrary Code Execution Vulnerability in Octopus Deploy Server
A vulnerability in Octopus Deploy Server allows a remote attacker to execute arbitrary code, potentially leading to full system compromise of the application instance.
CVE search metadata
CVE search record: CVE-2024-29837. Severity: high. CVSS: 8.8. EPSS: 0.51%. KEV: no. Product: Octopus Deploy Server (<= 2.04.560.31.03.2024). Brief: Arbitrary Code Execution Vulnerability in Octopus Deploy Server. Brief link: https://feed.craftedsignal.io/briefs/2026-09-octopus-deploy-rce/
Octopus Deploy Server contains a security vulnerability that permits a remote, unauthenticated attacker to achieve remote code execution (RCE) on the host system. This vulnerability, tracked as CVE-2024-29837, affects the core server component, which is widely used for automated software deployment and release management. Successful exploitation allows an adversary to gain full control over the application instance, enabling them to steal sensitive deployment credentials, modify application configurations, or pivot into connected infrastructure environments. Defenders should prioritize patching, as this vulnerability provides a direct pathway for full system compromise of build and deployment pipelines.
Impact
Successful exploitation of this vulnerability leads to full remote code execution on the Octopus Deploy Server. Given the role of this software in managing CI/CD pipelines, a compromise allows an attacker to inject malicious code into downstream software releases, exfiltrate API keys for cloud environments, and gain unauthorized access to managed target infrastructure. Organizations using Octopus Deploy as a central deployment hub are at high risk of supply chain compromise if their orchestration server is breached.
Recommendation
Prioritize patching all internet-facing and internal Octopus Deploy Server instances to the vendor-provided security update.
- Patch CVE-2024-29837 on all Octopus Deploy Server instances immediately.
- Audit deployment logs for unusual processes spawned by the Octopus Deploy service account or service binary.
- Restrict network access to the Octopus Deploy web interface to authorized management subnets only.
Immediate actions
Patch Octopus Deploy Server to resolve CVE-2024-29837.
Mitigations
Isolate Octopus Deploy management interface from the public internet.
CVE-2024-29837