CVE-2026-10569: IBM Devops Deploy

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step.

Affected products

  • IBM Devops Deploy: from 8.0.0.0, before 8.0.1.14 (fixed in 8.0.1.14); from 8.1.0.0, before 8.1.2.7 (fixed in 8.1.2.7); from 8.2.0.0, before 8.2.2.0 (fixed in 8.2.2.0)
  • IBM Urbancode Deploy: from 7.2.0.0, before 7.2.3.24 (fixed in 7.2.3.24); from 7.3.0.0, before 7.3.2.19 (fixed in 7.3.2.19)

Published 2026-07-30. Last modified 2026-08-10.