Junglewise Threat Intelligence

CVE-2026-12085: IBM UrbanCode Deploy sensitive information disclosure in API responses

CVE-2026-12085 · Severity: medium · CVSS 6.5 · Published 2026-06-30

Vendors: IBM.

Executive brief

IBM UrbanCode Deploy and DevOps Deploy, tools used to automate software deployments across an organization, are affected by a security flaw that leaks sensitive information. An authorized user could view internal configuration details and secrets that are normally hidden, which could then be used to launch further attacks against the corporate infrastructure. IBM has released updates to address this issue and recommends upgrading to the latest versions.

Technical details

IBM UrbanCode Deploy and DevOps Deploy are vulnerable to an information disclosure flaw (CWE-201) where sensitive configuration data and secrets are improperly included in API responses. The vulnerability is accessible over the network but requires the attacker to be authenticated with at least low-level privileges. An attacker can exploit this by intercepting or requesting specific API calls to retrieve credentials or system secrets, potentially facilitating lateral movement or further compromise of the deployment environment. The issue is resolved in versions 7.3.2.19, 8.0.1.14, 8.1.2.7, and 8.2.2.0.

Affected products

  • IBM UrbanCode Deploy / DevOps Deploy 7.3 through 7.3.2.18, 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, 8.2 through 8.2.1.0

Timeline

  • 2026-06-23: advisory: Initial publication by IBM
  • 2026-06-30: disclosed: NVD publication date

References