CVE-2020-12286: Octopus Deploy

Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.

In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example, a scoped user who is scoped to only one tenant can view server tasks scoped to any other tenant.

Affected products

  • Octopus Octopus Deploy: before 2019.12.9 (fixed in 2019.12.9); from 2020.1, before 2020.1.12 (fixed in 2020.1.12)

Published 2020-04-28. Last modified 2026-06-17.