CVE-2026-12702: Medium severity Octopus Deploy Octopus Deploy vulnerability
Published Jul 24, 2026
·Updated
In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.
Affected Software
5 affected components
Octopus Deploy Octopus Deploy
All of the following
Any of the following
Octopus Octopus Server>=2023.1.4189<2026.1.11587
Octopus Octopus Server>=2026.2.61<2026.2.13190
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Jul 24, 2026
CVE Published
via MITRE·08:29 AM
Data Sourced
via MITRE·08:29 AM
DescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-12702?
CVE-2026-12702 has a medium severity rating of 5.1 on the CVSS scale.
2
How do I fix CVE-2026-12702?
To fix CVE-2026-12702, update to the latest version of Octopus Deploy where the vulnerability is patched.
3
What are the risks associated with CVE-2026-12702?
The risk associated with CVE-2026-12702 is that unauthorized users may trigger deployments due to insufficient checks on project trigger actions.
4
Which versions of Octopus Deploy are affected by CVE-2026-12702?
CVE-2026-12702 affects certain older versions of Octopus Deploy prior to the security update.
5
When was CVE-2026-12702 published?
CVE-2026-12702 was published on July 24, 2026.