CVE-2026-12702

Summary

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.

Affected Software

VendorProductVersion RangeStatus
Octopus DeployOctopus Server2023.0.0 < 2026.1.11587affected
Octopus DeployOctopus Server2026.1.0 < 2026.1.11587affected
Octopus DeployOctopus Server2026.2.0 < 2026.2.13190affected

Weaknesses

  • Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References