Junglewise Threat Intelligence

CVE-2026-12086: IBM UrbanCode Deploy sensitive information disclosure in log files

CVE-2026-12086 · Severity: medium · CVSS 6.2 · Published 2026-06-30

Executive brief

IBM UrbanCode Deploy and DevOps Deploy, which are tools used to automate software deployments, contain a vulnerability where sensitive information is written to log files. An individual with local access to the system could read these logs to obtain confidential data. This could lead to unauthorized access to other systems or the exposure of credentials used during the deployment process.

Technical details

The vulnerability is classified as CWE-532 (Insertion of Sensitive Information into Log File). The IBM UrbanCode Deploy/DevOps Deploy installer and application components write sensitive data into log files with insufficient access controls or masking. A local attacker with access to the file system can read these logs to extract sensitive information without requiring elevated privileges. The issue affects multiple major versions (7.2, 7.3, 8.0, 8.1, and 8.2). IBM has released patches (7.2.3.24, 7.3.2.19, 8.0.1.14, 8.1.2.7, 8.2.2.0) to remediate the logging behavior.

Affected products

  • IBM UrbanCode Deploy (UCD) / DevOps Deploy 7.2 through 7.2.3.23, 7.3 through 7.3.2.18, 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, 8.2 through 8.2.1.0

Timeline

  • 2026-06-23: advisory: Initial publication by IBM
  • 2026-06-30: disclosed: NVD publication date

References

Related threats