CVE-2025-62327: HCL DevOps Deploy is susceptible to insufficiently protected credentials
Published Jan 7, 2026
·Updated
In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credential previously saved for performing authenticated LLM Queries.
Affected Software
2 affected components
HCL DevOps Deploy>=8.1.2.0<=8.1.2.3
Hcltechsw Hcl Devops Deploy>=8.1.2.0<8.1.2.3
Event History
Jan 7, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-62327?
CVE-2025-62327 has a severity rating that indicates a moderate risk due to potential unauthorized access to saved credentials.
2
How do I fix CVE-2025-62327?
To fix CVE-2025-62327, update HCL DevOps Deploy to version 8.1.2.4 or later.
3
What versions of HCL DevOps Deploy are affected by CVE-2025-62327?
CVE-2025-62327 affects HCL DevOps Deploy versions 8.1.2.0 to 8.1.2.3.
4
Who is at risk from CVE-2025-62327?
Users with LLM configuration privileges in affected versions of HCL DevOps Deploy are at risk from CVE-2025-62327.
5
What type of data is exposed due to CVE-2025-62327?
CVE-2025-62327 potentially exposes saved credentials used for performing authenticated LLM Queries.