Junglewise Threat Intelligence

CVE-2026-56457: HCL DevOps Deploy sensitive information exposure in output logs

CVE-2026-56457 · Severity: medium · CVSS 4.3 · Published 2026-06-29

Technologies: HCL Software DevOps Launch, HCL Software DevOps Deploy. Vendors: HCL Software.

Executive brief

HCL DevOps Deploy and HCL Launch, tools used to automate software deployments, are affected by a security flaw where sensitive information is improperly recorded in output logs. An authorized user with access to these logs could view sensitive values, such as credentials or configuration secrets, that were used during a deployment step. This could lead to unauthorized access to other systems or data within the deployment pipeline.

Technical details

HCL DevOps Deploy and HCL Launch (formerly IBM UrbanCode Deploy) are vulnerable to CWE-532 (Insertion of Sensitive Information into Log File). The vulnerability occurs when the application writes sensitive values related to deployment steps into the standard output logs. An attacker with network access and low-level authenticated privileges (PR:L) to view deployment logs can extract these sensitive values. The issue affects multiple version branches including 7.3.x, 8.0.x, 8.1.x, and 8.2.x. Users are advised to refer to HCL advisory KB0131694 for specific patching instructions.

Affected products

  • HCL Software DevOps Deploy / Launch 7.3-7.3.2.18, 8.0-8.0.1.13, 8.1-8.1.2.6, 8.2-8.2.1.0

Timeline

  • 2026-06-29: advisory
  • 2026-06-29: disclosed

References

Related threats