CVE-2026-12085: IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptable to an Insertion of Sensitive Information Into Sent Data vulnerability
IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM UrbanCode Deploy (UCD) / IBM DevOps Deployto a version that resolves this vulnerability.Fixed in 7.3.2.19 - Upgrade
Upgrade
IBM UrbanCode Deploy (UCD) / IBM DevOps Deployto a version that resolves this vulnerability.Fixed in 8.0.1.14 - Upgrade
Upgrade
IBM UrbanCode Deploy (UCD) / IBM DevOps Deployto a version that resolves this vulnerability.Fixed in 8.1.2.7 - Upgrade
Upgrade
IBM UrbanCode Deploy (UCD) / IBM DevOps Deployto a version that resolves this vulnerability.Fixed in 8.2.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12085?
CVE-2026-12085 has a medium severity rating of 6.5.
What systems are affected by CVE-2026-12085?
CVE-2026-12085 affects IBM UrbanCode Deploy versions 7.3 through 7.3.2.18 and IBM DevOps Deploy versions 8.0 through 8.0.1.13 and 8.1 through 8.1.2.6.
What type of vulnerability is CVE-2026-12085?
CVE-2026-12085 is an Insertion of Sensitive Information Into Sent Data vulnerability.
How can CVE-2026-12085 impact an organization?
CVE-2026-12085 may allow authenticated users to access sensitive configurations and secrets, leading to potential attacks against the system.
How do I fix CVE-2026-12085?
To fix CVE-2026-12085, users should update to the latest patched versions of IBM UrbanCode Deploy and IBM DevOps Deploy.