CVE-2026-12702
Received Received - Intake

Insufficient Authorization Check in Octopus Deploy

Vulnerability report for CVE-2026-12702, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: Octopus Deploy

Description

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
octopus_deploy octopus_server From 2023.x (inc) to 2026.2.x (inc)
octopus_deploy octopus_server to 2026.1.11587 (exc)
octopus_deploy octopus_server to 2026.2.13190 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Octopus Deploy allows an unauthorized user to trigger a deployment due to insufficient checks on project trigger actions. It affects versions 2023.x through 2026.2.x of Octopus Server.

Impact Analysis

An attacker could initiate unauthorized deployments, potentially leading to incorrect or malicious software being deployed in your environment. This could disrupt operations or introduce security risks.

Compliance Impact

This vulnerability could lead to unauthorized changes in software deployments, violating integrity and audit requirements in GDPR and HIPAA. Compliance may be compromised if deployments are not properly controlled.

Mitigation Strategies

Upgrade Octopus Server to version 2026.1.11587, 2026.2.13190, or later. No other mitigation exists. Download updates from the official Octopus Deploy website.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12702. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart