CVE-2026-10569 Details
Description
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step.
A vulnerability allowing the exposure of sensitive information has been identified in IBM UrbanCode Deploy versions 7.2 through 7.2.3.23, 7.3 through 7.3.2.18, and in IBM DevOps Deploy versions 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0. This vulnerability arises from plugin output logs, where sensitive values related to specific steps could be accessed by an attacker with log access.
Users are advised to upgrade to IBM UrbanCode Deploy version 7.2.3.24, 7.3.2.19, or to IBM DevOps Deploy versions 8.0.1.14, 8.1.2.7, or 8.2.2.0. Instructions for downloading these versions are available on the IBM Support Fix Central website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7277574 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm devops deploy | >= 8.0.0.0, < 8.0.1.14 >= 8.1.0.0, < 8.1.2.7 >= 8.2.0.0, < 8.2.2.0 |
CPE
Remediation
| |
| ibm urbancode deploy | >= 7.2.0.0, < 7.2.3.24 >= 7.3.0.0, < 7.3.2.19 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | Initial Analysis | [email protected] |
| Jul 30, 2026 | New CVE Received | [email protected] |
| Jul 30, 2026 | CVE Modified | CISA-ADP |