CVE-2018-12884: Octopus Deploy

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create Accounts under the Infrastructure menu.

Affected products

  • Octopus Octopus Deploy: version 3.0 only

Published 2018-06-26. Last modified 2026-06-17.