Junglewise Threat Intelligence

CVE-2026-12702: Octopus Deploy incorrect authorization in project triggers

CVE-2026-12702 · Severity: info · CVSS 5.1 · Published 2026-07-24

Executive brief

Octopus Deploy, a platform used to automate software releases, contains a security flaw where certain project triggers do not properly verify user permissions. This could allow an unauthorized user to initiate software deployments that they should not have access to control. Such unauthorized deployments could lead to unintended changes in production environments or operational disruptions.

Technical details

An incorrect authorization vulnerability exists in Octopus Server due to insufficient validation checks on project trigger actions. A network-based attacker with high privileges (PR:H) can bypass intended restrictions to trigger deployments they are not authorized to execute. The root cause is a failure to properly enforce permission checks within the project trigger component. This issue affects multiple major versions including 2023.x through 2026.2. Patches have been released in versions 2026.1.11587 and 2026.2.13190.

Affected products

  • Octopus Deploy Octopus Server 2023.x, 2024.x, 2025.x, 2026.1 before 2026.1.11587, 2026.2 before 2026.2.13190

Timeline

  • 2026-05-11: other: Vulnerability discovered
  • 2026-06-23: patched: Patch release date
  • 2026-07-15: advisory: Advisory release date
  • 2026-07-24: disclosed: CVE published

References

Related threats