CVE-2026-12084
Received Received - Intake

Cross-Origin Resource Sharing (CORS) Vulnerability in IBM DevOps Deploy

Vulnerability report for CVE-2026-12084, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-30

Last updated on: 2026-06-30

Assigner: IBM Corporation

Description

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-30
Last Modified
2026-06-30
Generated
2026-07-01
AI Q&A
2026-06-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
ibm devops_deploy From 8.1 (inc) to 8.1.2.6 (inc)
ibm devops_deploy From 8.2 (inc) to 8.2.1.0 (inc)
ibm ibm_devops_deploy From 8.1 (inc) to 8.1.2.6 (inc)
ibm ibm_devops_deploy From 8.2 (inc) to 8.2.1.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-942 The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM DevOps Deploy (also known as IBM UrbanCode Deploy) versions 8.1 through 8.1.2.6 and 8.2 through 8.2.1.0 have a vulnerability related to their Cross-Origin Resource Sharing (CORS) implementation.

The vulnerability occurs because the software does not restrict CORS domain access to only trusted domains, allowing any domain to interact with it.

This permissive cross-domain security policy can enable an attacker to perform privileged actions and retrieve sensitive information from the system.

Impact Analysis

This vulnerability can allow attackers to carry out privileged actions within IBM DevOps Deploy and access sensitive information.

Because the domain restriction is not enforced, malicious websites could exploit this to perform unauthorized operations or steal data.

The CVSS base score of 5.4 indicates a moderate severity, meaning the impact is significant but not critical.

Mitigation Strategies

To mitigate this vulnerability, IBM recommends upgrading IBM DevOps Deploy (UCD) to versions 8.1.2.7, 8.2.2.0, or later.

No workarounds are provided for this vulnerability.

Compliance Impact

The vulnerability in IBM DevOps Deploy involves a permissive Cross-Origin Resource Sharing (CORS) policy that allows attackers to perform privileged actions and access sensitive information. This exposure of sensitive information could potentially impact compliance with data protection regulations such as GDPR and HIPAA, which require strict controls over access to personal and sensitive data.

However, the provided information does not explicitly mention the impact on compliance with specific standards or regulations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12084. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart