IBMCVE-2026-10569
UCD - IBM: information disclosure
Medium4.3CVE-2026-10569 · Published Jul 30, 2026 · updated Aug 10, 2026
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| UCD - IBM DevOps Deploy Product | >= 8.0, <= 8.0.1.13 | No fix yet |
| >= 8.1, <= 8.1.2.6 | No fix yet | |
| >= 8.2, <= 8.2.1.0 | No fix yet | |
| UCD - IBM UrbanCode Deploy Product | >= 7.2, <= 7.2.3.23 | No fix yet |
| >= 7.3, <= 7.3.2.18 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-200
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 30 | IBM WebSphere Application Server: remote code execution | High8.5 | No fix yet |
| Jul 30 | IBM Langflow OSS: code injection | Critical9.9 | No fix yet |
| Jul 30 | IBM Langflow OSS: improper input validation | Critical9.9 | No fix yet |
| Jul 30 | IBM Langflow OSS: attacker could access another user's private vector | High8.1 | No fix yet |
| Jul 30 | IBM Langflow OSS: path traversal | High7.5 | No fix yet |
| Jul 30 | IBM HMC: remote code execution | Critical9.8 | No fix yet |