CVE-2026-78658
Received Received - Intake

Information Disclosure in IBM UrbanCode Deploy

Vulnerability report for CVE-2026-78658, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: IBM Corporation

Description

IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an formation disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside unsecure properties. An authenticated user with permissions to view deployment request details could exploit this flaw via the UI or API to view sensitive values in plain text that should otherwise be redacted.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
ibm urbancode_deploy From 7.2 (inc) to 7.2.3.25 (inc)
ibm urbancode_deploy From 7.3 (inc) to 7.3.2.20 (inc)
ibm devops_deploy From 8.0 (inc) to 8.0.1.15 (inc)
ibm devops_deploy From 8.1 (inc) to 8.1.2.8 (inc)
ibm devops_deploy From 8.2 (inc) to 8.2.2.1 (inc)
ibm urban_code_deploy From 7.2 (inc) to 7.2.3.25 (inc)
ibm urban_code_deploy From 7.3 (inc) to 7.3.2.20 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-212 The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an information disclosure flaw in IBM UrbanCode Deploy and IBM DevOps Deploy. It occurs when secure property values starting with certain non-ASCII characters cause the redaction engine to fail. This exposes sensitive ASCII secure values embedded in unsecure properties to authenticated users with deployment request access via UI or API.

Detection Guidance

This vulnerability requires checking IBM UrbanCode Deploy or DevOps Deploy versions and configurations. Review deployed versions against affected ranges (7.2-7.3.2.20, 8.0-8.2.2.1). Check deployment logs for unredacted sensitive values in UI or API responses. No specific commands are provided in the resources.

Impact Analysis

An attacker with access to deployment requests could view sensitive data like passwords or API keys that should be redacted. This could lead to unauthorized access to systems, data breaches, or further exploitation of affected environments.

Compliance Impact

This vulnerability could lead to unauthorized exposure of personal or sensitive data, violating GDPR and HIPAA requirements for data protection and confidentiality. Organizations may face compliance penalties and reputational damage.

Mitigation Strategies

Upgrade to fixed versions: 7.2.3.26, 7.3.2.21, 8.0.1.16, 8.1.2.9, 8.2.2.2 or later. No workarounds exist. Monitor deployment requests for exposed sensitive data and restrict user permissions to view deployment details.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78658. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart