IBM UCD 7.2-7.3.2.20 Redaction Disclosure via UI/API
CVE-2026-78658 Published on September 4, 2026
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerability
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an formation disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside unsecure properties. An authenticated user with permissions to view deployment request details could exploit this flaw via the UI or API to view sensitive values in plain text that should otherwise be redacted.
Vulnerability Analysis
CVE-2026-78658 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Improper Removal of Sensitive Information Before Storage or Transfer
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
Products Associated with CVE-2026-78658
stack.watch emails you whenever new vulnerabilities are published in Ucd Ibm Urbancode Deploy or Ucd Ibm Devops Deploy. Just hit a watch button to start following.
Affected Versions
UCD - IBM UrbanCode Deploy:- Version 7.2.0, <= 7.2.3.25 is affected.
- Version 7.3.0, <= 7.3.2.20 is affected.
- Version 8.0, <= 8.0.1.15 is affected.
- Version 8.1.0, <= 8.1.2.8 is affected.
- Version 8.2.0, <= 8.2.2.1 is affected.