IBM UrbanCode Deploy 7.x/8.x: Exposure of Sensitive Info in Plugin Logs
CVE-2026-10569 Published on July 30, 2026
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Exposure of Sensitive Information Vulnerability
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step.
Vulnerability Analysis
CVE-2026-10569 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-10569 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2026-10569
stack.watch emails you whenever new vulnerabilities are published in Ucd Ibm Urbancode Deploy or Ucd Ibm Devops Deploy. Just hit a watch button to start following.
Affected Versions
UCD - IBM UrbanCode Deploy:- Version 7.2, <= 7.2.3.23 is affected.
- Version 7.3, <= 7.3.2.18 is affected.
- Version 8.0, <= 8.0.1.13 is affected.
- Version 8.1, <= 8.1.2.6 is affected.
- Version 8.2, <= 8.2.1.0 is affected.