CyberRota Analysis
AI-GeneratedAffected versions of Octopus Deploy have insufficient validation on project trigger actions, enabling unauthorized users to initiate deployments without proper permissions. This vulnerability poses a significant risk of unauthorized access and potential disruption to deployment processes. Organizations using Octopus Deploy should prioritize addressing this issue to safeguard their deployment environments.
CVE
CVE-2026-12702
Severity
MEDIUM
CVSS
4.9
EPSS
0.19%
Original NVD Description
In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.
Related CVEs
Other vulnerabilities affecting the same vendor(s)