
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-12702 is an improper access control vulnerability in Octopus Deploy that allows an unauthorized user to trigger a deployment by exploiting insufficient checks on project trigger actions. It affects Octopus Server versions from 2023.0.0 up to (but not including) 2026.1.11587, and versions 2026.2.0 up to (but not including) 2026.2.13190. The vulnerability was published on July 24, 2026, with a patch made available the same day. It carries a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, Octopus Advisory).
The root cause is classified as CWE-284 (Improper Access Control): the application fails to adequately validate whether a user is authorized before allowing them to invoke project trigger actions, enabling an unauthorized actor to initiate deployments. The attack vector is network-based, requires no user interaction, and has low attack complexity, though the CVSS v4.0 scoring notes that high privileges are required — suggesting the attacker may need some level of account access rather than being fully unauthenticated. No public proof-of-concept or detailed technical write-up has been disclosed as of the time of reporting (GitHub Advisory, Octopus Advisory).
Successful exploitation allows an unauthorized user to trigger deployment actions on projects within Octopus Deploy without proper authorization, resulting in a low integrity impact to the vulnerable system. This could lead to unintended or malicious deployments being executed against target environments, potentially introducing unauthorized code or configuration changes into production or staging infrastructure. Confidentiality and availability of the Octopus Server itself are not directly impacted, but downstream systems receiving unauthorized deployments may be at risk (GitHub Advisory, Octopus Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of reporting. The NVD SSVC assessment confirms exploitation is "none" and the vulnerability is not automatable. The EPSS score is approximately 0.24% (14th percentile), indicating a low near-term probability of exploitation. CVE-2026-12702 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Octopus Advisory).
Octopus Deploy released patched versions on July 24, 2026: upgrade to 2026.1.11587 or later for the 2023.x/2026.1.x release lines, or to 2026.2.13190 or later for the 2026.2.x line. As an interim measure, administrators should review and enforce proper access controls and authorization checks for project trigger actions, and audit recent deployment trigger history to identify any unauthorized activity. Restricting network access to the Octopus Server API to trusted users and networks can reduce exposure while patching is completed (Octopus Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."