CVE-2026-78658: IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerability

Published Sep 3, 2026
·
Updated

IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an formation disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside unsecure properties.

An authenticated user with permissions to view deployment request details could exploit this flaw via the UI or API to view sensitive values in plain text that should otherwise be redacted.

Affected Software

5 affected components
IBM UCD - IBM UrbanCode Deploy<=7.2 - 7.2.3.25
IBM UCD - IBM UrbanCode Deploy<=7.3 - 7.3.2.20
IBM UCD - IBM DevOps Deploy<=8.0 - 8.0.1.15
IBM UCD - IBM DevOps Deploy<=8.1 - 8.1.2.8
IBM UCD - IBM DevOps Deploy<=8.2 - 8.2.2.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) to a version that resolves this vulnerability.

    Fixed in 7.2.3.26
  2. Upgrade

    Upgrade IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) to a version that resolves this vulnerability.

    Fixed in 7.3.2.21
  3. Upgrade

    Upgrade IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) to a version that resolves this vulnerability.

    Fixed in 8.0.1.16
  4. Upgrade

    Upgrade IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) to a version that resolves this vulnerability.

    Fixed in 8.1.2.9
  5. Upgrade

    Upgrade IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) to a version that resolves this vulnerability.

    Fixed in 8.2.2.2
  6. Configuration

    As a temporary mitigation per IBM: if a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside unsecure properties—adjust the secure property values so they do not start with those non-ASCII characters until the upgrade is applied.

    IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) redaction engine Secure property redaction behavior for secure values embedded in unsecure properties = Ensure secure properties do not start with certain non-ASCII characters that can cause the redaction engine to fail to mask subsequent ASCII secure values embedded inside unsecure properties

Event History

Sep 3, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 4, 2026
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
RemedyDescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user who has permission to view deployment request details can exploit it through either the UI or API. The issue exposes sensitive values that should have been redacted.

2

What configuration is required for exposure?

A deployment must use a secure property beginning with certain non-ASCII characters, and subsequent ASCII secure values must be embedded in unsecure properties. Under those conditions, the redaction engine may fail to mask the ASCII secure values.

3

Which product versions are affected?

Affected IBM UrbanCode Deploy versions are 7.2 through 7.2.3.25 and 7.3 through 7.3.2.20. Affected IBM DevOps Deploy versions are 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203