Medium severity6.5NVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026
CVE-2026-12085
CVE-2026-12085
Description
IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
Affected products
4cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:*range: >=8.0.0.0,<8.0.1.14
- (no CPE)range: 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*range: >=7.3.0.0,<7.3.2.19
- (no CPE)range: 7.3 through 7.3.2.18
Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7277577nvdVendor Advisory
News mentions
0No linked articles in our index yet.