CVE-2026-10569: IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Exposure of Sensitive Information Vulnerability
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM UrbanCode Deploy (UCD) / IBM DevOps Deployto a version that resolves this vulnerability.Fixed in 7.2.3.24 - Upgrade
Upgrade
IBM UrbanCode Deploy (UCD) / IBM DevOps Deployto a version that resolves this vulnerability.Fixed in 7.3.2.19 - Upgrade
Upgrade
IBM UrbanCode Deploy (UCD) / IBM DevOps Deployto a version that resolves this vulnerability.Fixed in 8.0.1.14 - Upgrade
Upgrade
IBM UrbanCode Deploy (UCD) / IBM DevOps Deployto a version that resolves this vulnerability.Fixed in 8.1.2.7 - Upgrade
Upgrade
IBM UrbanCode Deploy (UCD) / IBM DevOps Deployto a version that resolves this vulnerability.Fixed in 8.2.2.0 - Operational
If attackers may have accessed plugin output logs containing sensitive values, review the logs for exposed information and treat any affected credentials/secrets as potentially compromised.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10569?
The severity of CVE-2026-10569 is medium with a score of 4.3.
What is CVE-2026-10569 about?
CVE-2026-10569 is an Exposure of Sensitive Information Vulnerability in IBM UrbanCode Deploy that affects specific versions of the software.
How do I fix CVE-2026-10569?
To fix CVE-2026-10569, upgrade IBM UrbanCode Deploy to the latest version that addresses the vulnerability.
Which versions are affected by CVE-2026-10569?
CVE-2026-10569 affects IBM UrbanCode Deploy 7.2 through 7.2.3.23, 7.3 through 7.3.2.18, and IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0.
What type of vulnerability is CVE-2026-10569 classified as?
CVE-2026-10569 is classified as an Exposure of Sensitive Information vulnerability.