Description
In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.
Published: 2026-07-24
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Octopus Deploy Server is an improper authorization weakness (CWE‑284). Insufficient checks on project trigger actions allow an unauthorized user to initiate a deployment.

Affected Systems

Octopus Deploy: Octopus Server is the affected product. The advisory does not disclose specific version ranges, but the flaw exists in any Octopus Server version that permits project triggers without proper permission verification.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity, and the EPSS score of < 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA KEV. The description does not explicitly state the attack vector; it is inferred that an attacker would need access to the Octopus Server management interface, typically through the web portal or API, to trigger the deployment.

Generated by OpenCVE AI on August 5, 2026 at 01:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Octopus Server patch that resolves the trigger access control flaw.
  • Configure role‑based permissions so that only authorized users can trigger deployments.
  • Monitor Octopus Server logs for unexpected deployment triggers and set up alerts for anomalous activity.

Generated by OpenCVE AI on August 5, 2026 at 01:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Deployment Trigger Exploit in Octopus Server

Sun, 02 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Deployment Trigger Exploit in Octopus Server

Sat, 01 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Deployment Trigger via Insufficient Project Trigger Checks

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Octopus
Octopus octopus Server
Vendors & Products Octopus
Octopus octopus Server

Sun, 26 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Deployment Trigger via Insufficient Project Trigger Checks

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Description In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Octopus Octopus Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Octopus

Published:

Updated: 2026-07-24T12:36:31.660Z

Reserved: 2026-06-19T10:14:04.133Z

Link: CVE-2026-12702

cve-icon Vulnrichment

Updated: 2026-07-24T12:36:23.557Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-24T09:16:22.900

Modified: 2026-07-28T16:25:15.680

Link: CVE-2026-12702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:15:03Z

Weaknesses