CVE-2026-12702 Details
Description
In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.
A vulnerability exists in Octopus Deploy that allows unauthorized users to trigger deployments due to insufficient checks on project trigger actions. This issue affects Octopus Server versions 2023.x, 2024.x, 2025.x, all 2026.1 versions prior to 2026.1.11587, and all 2026.2 versions before 2026.2.13190. The vulnerability arises from inadequate authorization controls, enabling unauthorized deployment actions.
Users are advised to upgrade to Octopus Server version 2026.2.13219 or, if on an earlier version, to upgrade to 2026.1.11587 or greater. The latest and previous versions of Octopus Server can be downloaded from the Octopus Deploy website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://advisories.octopus.com/post/2026/sa2026-06 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| octopus octopus server | >= 2023.1.4189, < 2026.1.11587 >= 2026.2.61, < 2026.2.13190 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 17, 2026 | Initial Analysis | [email protected] |
| Jul 24, 2026 | CVE Modified | CISA-ADP |
| Jul 24, 2026 | New CVE Received | [email protected] |