CVE-2026-12702: Octopus Server
Medium severity, CVSS 4.9. EPSS: 0.3% chance of exploitation in the next 30 days.
In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.
Affected products
- Octopus Octopus Server: from 2023.1.4189, before 2026.1.11587 (fixed in 2026.1.11587); from 2026.2.61, before 2026.2.13190 (fixed in 2026.2.13190)
Published 2026-07-24. Last modified 2026-08-17.