A vulnerability, which was classified as very critical, was found in Octopus Deploy Octopus Server up to 2026.1.11586/2026.2.13189. Affected by this vulnerability is an unknown functionality of the component Project Trigger Actions. Executing a manipulation can lead to improper authorization.

This vulnerability appears as CVE-2026-12702. The attack may be performed from remote. There is no available exploit.

You should upgrade the affected component.