Insufficient Project Trigger Action Checks in Octopus Deploy Software by Octopus Deploy
CVE-2026-12702

5.1MEDIUM

Key Information:

Vendor
CVE Published:
24 July 2026

What is CVE-2026-12702?

Affected versions of Octopus Deploy are susceptible to a vulnerability that allows insufficient verification of project trigger actions. This flaw permits unauthorized users to initiate deployments without proper authentication, posing significant risks to project integrity and security. Organizations should ensure they are using the latest version of the software to mitigate this exposure.

Affected Version(s)

Octopus Server Windows 2023.0.0 < 2026.1.11587

Octopus Server Windows 2026.1.0 < 2026.1.11587

Octopus Server Windows 2026.2.0 < 2026.2.13190

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability was found by hackingsal
.