Description
HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
Published: 2026-07-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in HCL DevOps Deploy / HCL Launch allows an authenticated user to receive API responses that contain sensitive configurations and secrets. The disclosure of such sensitive data could enable attackers to compromise the system. The weakness aligns with CWE-201, an insertion of sensitive information into sent data.

Affected Systems

HCLSoftware’s HCL DevOps Deploy / HCL Launch product is affected. Specific affected versions were not disclosed in the available data, so all released versions of the product should be evaluated.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack path requires the attacker to authenticate to the application, after which they can trigger the problematic API endpoints and receive the leaked information. Consequently, any authenticated user—either legitimate or compromised—has the potential to abuse this weakness.

Generated by OpenCVE AI on July 29, 2026 at 12:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply upgrade to a version that fixes the issue, as described in HCL Software’s support article KB0131697
  • Revoke or restrict the privileges of users who do not require full API access limit the scope of potential data exposure
  • Implement logging and monitoring of API responses to detect any unintended release of sensitive information

Generated by OpenCVE AI on July 29, 2026 at 12:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech devops Deploy
Hcltech launch
Vendors & Products Hcltech
Hcltech devops Deploy
Hcltech launch

Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
Title HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Hcltech Devops Deploy Launch
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-09T12:23:15.700Z

Reserved: 2026-06-22T13:38:32.650Z

Link: CVE-2026-56460

cve-icon Vulnrichment

Updated: 2026-07-09T12:23:10.854Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:45:03Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data