CVE-2026-12085

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/06/2026
Last modified:
02/07/2026

Description

IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:* 8.0.0.0 (including) 8.0.1.14 (excluding)
cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:* 8.1.0.0 (including) 8.1.2.7 (excluding)
cpe:2.3:a:ibm:devops_deploy:*:*:*:*:*:*:*:* 8.2.0.0 (including) 8.2.1.0 (excluding)
cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:* 7.3.0.0 (including) 7.3.2.19 (excluding)


References to Advisories, Solutions, and Tools