CVE-2026-78658: IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerability
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an formation disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside unsecure properties.
An authenticated user with permissions to view deployment request details could exploit this flaw via the UI or API to view sensitive values in plain text that should otherwise be redacted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)to a version that resolves this vulnerability.Fixed in 7.2.3.26 - Upgrade
Upgrade
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)to a version that resolves this vulnerability.Fixed in 7.3.2.21 - Upgrade
Upgrade
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)to a version that resolves this vulnerability.Fixed in 8.0.1.16 - Upgrade
Upgrade
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)to a version that resolves this vulnerability.Fixed in 8.1.2.9 - Upgrade
Upgrade
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)to a version that resolves this vulnerability.Fixed in 8.2.2.2 - Configuration
As a temporary mitigation per IBM: if a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside unsecure properties—adjust the secure property values so they do not start with those non-ASCII characters until the upgrade is applied.
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) redaction engine Secure property redaction behavior for secure values embedded in unsecure properties = Ensure secure properties do not start with certain non-ASCII characters that can cause the redaction engine to fail to mask subsequent ASCII secure values embedded inside unsecure properties
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user who has permission to view deployment request details can exploit it through either the UI or API. The issue exposes sensitive values that should have been redacted.
What configuration is required for exposure?
A deployment must use a secure property beginning with certain non-ASCII characters, and subsequent ASCII secure values must be embedded in unsecure properties. Under those conditions, the redaction engine may fail to mask the ASCII secure values.
Which product versions are affected?
Affected IBM UrbanCode Deploy versions are 7.2 through 7.2.3.25 and 7.3 through 7.3.2.20. Affected IBM DevOps Deploy versions are 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1.