CVE-2026-12085: IBM Devops Deploy
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
Affected products
- IBM Devops Deploy: from 8.0.0.0, before 8.0.1.14 (fixed in 8.0.1.14); from 8.1.0.0, before 8.1.2.7 (fixed in 8.1.2.7); from 8.2.0.0, before 8.2.1.0 (fixed in 8.2.1.0)
- IBM Urbancode Deploy: from 7.3.0.0, before 7.3.2.19 (fixed in 7.3.2.19)
Published 2026-06-30. Last modified 2026-07-02.