Junglewise Threat Intelligence

CVE-2026-56459: HCL DevOps Deploy sensitive information disclosure in log files

CVE-2026-56459 · Severity: medium · CVSS 6.2 · Published 2026-07-09

Technologies: HCL Software DevOps Launch, HCL Software DevOps Deploy. Vendors: HCL Software.

Executive brief

HCL DevOps Deploy and HCL Launch, tools used for automating software deployments, are affected by a security flaw where sensitive information is recorded in system log files. An individual with local access to the server could read these logs to obtain confidential data. This could lead to unauthorized access to other systems or the exposure of internal configuration details.

Technical details

HCL DevOps Deploy and HCL Launch (formerly IBM UrbanCode Deploy) contain a vulnerability classified as CWE-532 (Insertion of Sensitive Information into Log File). The application incorrectly records potentially sensitive data into log files stored on the local file system. An attacker with local access to the host machine can read these files without requiring elevated privileges or specific user interaction. This exposure can lead to the compromise of credentials, tokens, or system configurations. Affected versions include the 7.3, 8.0, 8.1, and 8.2 release streams up to their respective patched levels.

Affected products

  • HCL Software DevOps Deploy / Launch 7.3-7.3.2.18, 8.0-8.0.1.13, 8.1-8.1.2.6, 8.2-8.2.1.0

Timeline

  • 2026-07-09: disclosed
  • 2026-07-09: advisory

References

Related threats