CVE-2026-12702: Octopus Server

Medium severity, CVSS 4.9. EPSS: 0.3% chance of exploitation in the next 30 days.

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.

Affected products

  • Octopus Octopus Server: from 2023.1.4189, before 2026.1.11587 (fixed in 2026.1.11587); from 2026.2.61, before 2026.2.13190 (fixed in 2026.2.13190)

Published 2026-07-24. Last modified 2026-08-17.