CVE-2026-56459: HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure
Published Jul 9, 2026
·Updated
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log files that could be read by a local user.
Affected Software
5 affected components
HCL DevOps Deploy / HCL Launch
Hcltechsw Hcl Devops Deploy>=8.0.0.0<8.0.1.14
Hcltechsw Hcl Devops Deploy>=8.1.0.0<8.1.2.7
Hcltechsw Hcl Devops Deploy>=8.2.0.0<8.2.2.0
Hcltechsw Hcl Launch>=7.3.0.0<7.3.2.19
Event History
Jul 9, 2026
CVE Published
via MITRE·08:25 AM
Data Sourced
via MITRE·08:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-56459?
The severity of CVE-2026-56459 is medium with a score of 6.2.
2
What type of vulnerability is CVE-2026-56459?
CVE-2026-56459 is a sensitive information disclosure vulnerability.
3
How does CVE-2026-56459 impact HCL DevOps Deploy / HCL Launch?
CVE-2026-56459 allows potentially sensitive information to be disclosed through log files accessible to local users.
4
Is there a known fix for CVE-2026-56459?
As of now, there is no specific fix mentioned for CVE-2026-56459.
5
Who is affected by CVE-2026-56459?
Users of HCL DevOps Deploy and HCL Launch are affected by CVE-2026-56459.