Junglewise Threat Intelligence

CVE-2026-56460: HCL DevOps Deploy and Launch sensitive information disclosure in API

CVE-2026-56460 · Severity: medium · CVSS 6.5 · Published 2026-07-09

Technologies: HCL Software DevOps Launch, HCL Software DevOps Deploy. Vendors: HCL Software.

Executive brief

HCL DevOps Deploy and HCL Launch, tools used for automating software deployments, are affected by a security flaw that reveals sensitive configuration data and secrets. An authorized user of the system could access this information through standard application interfaces. This exposed data could be used by an attacker to gain deeper access to the environment or compromise other connected systems.

Technical details

HCL DevOps Deploy and HCL Launch are vulnerable to sensitive information disclosure (CWE-201) within API responses. The vulnerability allows an authenticated user with network access to the API to retrieve sensitive configuration details and secrets that should otherwise be protected. This occurs because the application fails to properly redact or filter sensitive data before sending it to the client. An attacker can leverage this information to facilitate further attacks against the deployment infrastructure. The issue affects multiple version branches including 7.3, 8.0, 8.1, and 8.2.

Affected products

  • HCL Software DevOps Deploy / Launch 7.3-7.3.2.18, 8.0-8.0.1.13, 8.1-8.1.2.6, 8.2-8.2.1.0

Timeline

  • 2026-07-09: disclosed: Initial publication of the CVE record

References

Related threats