CVE-2026-56460: HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerability
Published Jul 9, 2026
·Updated
HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
Affected Software
6 affected components
HCL DevOps Deploy
HCL Launch
Hcltechsw Hcl Devops Deploy>=8.0.0.0<8.0.1.14
Hcltechsw Hcl Devops Deploy>=8.1.0.0<8.1.2.7
Hcltechsw Hcl Devops Deploy>=8.2.0.0<8.2.2.0
Hcltechsw Hcl Launch>=7.3.0.0<7.3.2.19
Event History
Jul 9, 2026
CVE Published
via MITRE·09:09 AM
Data Sourced
via MITRE·09:09 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-56460?
The severity of CVE-2026-56460 is rated medium with a score of 6.5.
2
What type of vulnerability is CVE-2026-56460?
CVE-2026-56460 is an Insertion of Sensitive Information Into Sent Data vulnerability.
3
What software is affected by CVE-2026-56460?
CVE-2026-56460 affects HCL DevOps Deploy and HCL Launch.
4
What impact does CVE-2026-56460 have on users?
CVE-2026-56460 can disclose sensitive configurations and secrets to authenticated users, leading to potential further attacks.
5
How do I remediate CVE-2026-56460?
Remediation for CVE-2026-56460 should focus on ensuring that sensitive information is not included in API responses.