Skip to content
IBMCVE-2026-10569

UCD - IBM: information disclosure

Medium4.3CVE-2026-10569 · Published Jul 30, 2026 · updated Aug 10, 2026

IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step.

IBM advisory

Affected versions

PackageAffectedFixed in
UCD - IBM DevOps Deploy
Product
>= 8.0, <= 8.0.1.13No fix yet
>= 8.1, <= 8.1.2.6No fix yet
>= 8.2, <= 8.2.1.0No fix yet
UCD - IBM UrbanCode Deploy
Product
>= 7.2, <= 7.2.3.23No fix yet
>= 7.3, <= 7.3.2.18No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-200

More IBM advisories

All IBM
Advisory
IBM WebSphere Application Server: remote code execution
High8.5Jul 30
IBM Langflow OSS: code injection
Critical9.9Jul 30
IBM Langflow OSS: improper input validation
Critical9.9Jul 30
IBM Langflow OSS: attacker could access another user's private vector
High8.1Jul 30
IBM Langflow OSS: path traversal
High7.5Jul 30
IBM HMC: remote code execution
Critical9.8Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.