CVE-2026-12086: IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Insertion of Sensitive Information into Log File Vulnerability
IBM DevOps Deploy stores potentially sensitive information in log files that could be read by a local user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)to a version that resolves this vulnerability.Fixed in 7.2.3.24 - Upgrade
Upgrade
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)to a version that resolves this vulnerability.Fixed in 7.3.2.19 - Upgrade
Upgrade
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)to a version that resolves this vulnerability.Fixed in 8.0.1.14 - Upgrade
Upgrade
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)to a version that resolves this vulnerability.Fixed in 8.1.2.7 - Upgrade
Upgrade
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)to a version that resolves this vulnerability.Fixed in 8.2.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12086?
The severity of CVE-2026-12086 is rated as medium with a score of 6.2.
How do I fix CVE-2026-12086?
To fix CVE-2026-12086, upgrade to the latest version of IBM UrbanCode Deploy or IBM DevOps Deploy that addresses this vulnerability.
What types of information are affected by CVE-2026-12086?
CVE-2026-12086 involves the potential logging of sensitive information that could be accessed by local users.
Which versions are impacted by CVE-2026-12086?
CVE-2026-12086 affects IBM UrbanCode Deploy versions 7.2 through 7.3.2.18 and IBM DevOps Deploy versions 8.0 through 8.2.1.0.
Who can exploit CVE-2026-12086?
CVE-2026-12086 can be exploited by local users who have access to the log files containing sensitive information.