CVE-2026-10569
Awaiting Analysis Awaiting Analysis - Queue

IBM UrbanCode Deploy Plugin Log Information Exposure

Vulnerability report for CVE-2026-10569, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: IBM Corporation

Description

IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
ibm urbancode_deploy From 7.2 (inc) to 7.2.3.23 (inc)
ibm urbancode_deploy From 7.3 (inc) to 7.3.2.18 (inc)
ibm devops_deploy From 8.0 (inc) to 8.0.1.13 (inc)
ibm devops_deploy From 8.1 (inc) to 8.1.2.6 (inc)
ibm devops_deploy From 8.2 (inc) to 8.2.1.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM UrbanCode Deploy and IBM DevOps Deploy versions have an exposure of sensitive information vulnerability in plugin output logs. An attacker with log access could potentially obtain sensitive values related to specific steps in the deployment process.

Detection Guidance

This vulnerability involves sensitive information exposure in plugin output logs. Detection requires checking UCD server logs for plugin steps that may log sensitive values. Review logs for any plaintext credentials, tokens, or configuration details in plugin outputs. No specific commands are provided in the CVE details.

Impact Analysis

If exploited, this vulnerability could allow unauthorized individuals to access sensitive data such as credentials or configuration details logged during deployment steps. This may lead to further security breaches or data leaks depending on the exposed information.

Compliance Impact

The vulnerability exposes sensitive information in plugin output logs, which could lead to unauthorized access to confidential data. This may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data privacy) if such data includes personal or protected health information.

Mitigation Strategies

Review and restrict access to plugin output logs to prevent unauthorized access to sensitive information. Ensure only authorized personnel can view logs containing step-related data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10569. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart