CVE-2026-67071: Hclsoftware Hcl Devops Deploy / Hcl Launch

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside insecure properties.

Affected products

Published 2026-09-17. Last modified 2026-09-18.