SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78658

MEDIUM · CVSS 6.5 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM UrbanCode Deploy and IBM DevOps Deploy versions 7.2 through 8.2.2.1 are vulnerable to an information disclosure flaw that can expose sensitive data due to improper handling of redacted property values. An authenticated user with access to deployment request details may exploit this vulnerability to view secure values in plain text, undermining data confidentiality. Organizations utilizing these versions should prioritize remediation to protect sensitive information from unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-78658
Severity
MEDIUM
CVSS
6.5
EPSS
0.27%

Original NVD Description

IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an formation disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside unsecure properties. An authenticated user with permissions to view deployment request details could exploit this flaw via the UI or API to view sensitive values in plain text that should otherwise be redacted.