IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25
Medium6.5CVE-2026-78658 · Published Sep 4, 2026 · updated Sep 10, 2026
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an formation disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside unsecure properties. An authenticated user with permissions to view deployment request details could exploit this flaw via the UI or API to view sensitive values in plain text that should otherwise be redacted.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| UCD - IBM DevOps Deploy Product | >= 8.0, <= 8.0.1.15 | No fix yet |
| >= 8.1.0, <= 8.1.2.8 | No fix yet | |
| >= 8.2.0, <= 8.2.2.1 | No fix yet | |
| UCD - IBM UrbanCode Deploy Product | >= 7.2.0, <= 7.2.3.25 | No fix yet |
| >= 7.3.0, <= 7.3.2.20 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-212
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 4 | IBM i: improper authorization | High8.1 | No fix yet |
| Sep 4 | IBM i: improper authentication | High8.1 | No fix yet |
| Sep 4 | IBM i: integer overflow | Medium6.3 | No fix yet |
| Sep 4 | IBM ContextForge MCP Gateway: privilege escalation | High8.8 | No fix yet |
| Sep 4 | IBM ContextForge MCP Gateway - Translate utility: information disclosure | High7.4 | No fix yet |
| Sep 4 | IBM Langflow OSS: path traversal | Medium5.4 | No fix yet |