CVE-2026-12085

IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
References
Link Resource
https://www.ibm.com/support/pages/node/7277577 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*

History

02 Jul 2026, 18:35

Type Values Removed Values Added
First Time Ibm
Ibm devops Deploy
Ibm urbancode Deploy
CPE cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7277577 - () https://www.ibm.com/support/pages/node/7277577 - Vendor Advisory
CWE NVD-CWE-noinfo

30 Jun 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-30 20:17

Updated : 2026-07-02 18:35


NVD link : CVE-2026-12085

Mitre link : CVE-2026-12085

CVE.ORG link : CVE-2026-12085


JSON object : View

Products Affected

ibm

  • devops_deploy
  • urbancode_deploy
CWE
CWE-201

Insertion of Sensitive Information Into Sent Data

NVD-CWE-noinfo