Impact
The vulnerability in Octopus Deploy Server is an improper authorization weakness (CWE‑284). Insufficient checks on project trigger actions allow an unauthorized user to initiate a deployment.
Affected Systems
Octopus Deploy: Octopus Server is the affected product. The advisory does not disclose specific version ranges, but the flaw exists in any Octopus Server version that permits project triggers without proper permission verification.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the EPSS score of < 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA KEV. The description does not explicitly state the attack vector; it is inferred that an attacker would need access to the Octopus Server management interface, typically through the web portal or API, to trigger the deployment.
OpenCVE Enrichment