Description
HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside insecure properties.
Published: 2026-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in the redaction engine that improperly removes sensitive information when processing secure property values. If a deployment configuration contains a secure property starting with certain non-ASCII characters, the engine may fail to mask ASCII secure values embedded inside insecure properties, leading to exposure of confidential data. This weakness is classified as CWE-212, an improper removal of sensitive information before storage or transfer.

Affected Systems

The affected product is HCLSoftware HCL DevOps Deploy / HCL Launch. No specific versions are indicated in the available data, so it is recommended to verify all deployed instances.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity risk. The EPSS score of less than 1% suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack path involves an attacker modifying a deployment configuration to insert a secure property that begins with non-ASCII characters; this can then trigger the redaction failure and disclose sensitive values. No publicly available exploit is known, but the combination of a remote configuration ability and the flaw means that any user with deployment privileges could potentially exploit this weakness.

Generated by OpenCVE AI on September 19, 2026 at 00:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest HCL DevOps Deploy / HCL Launch patch or update available from HCL support to address the redaction flaw.
  • Review and modify secure property configurations to avoid using non-ASCII characters at the start of secure property keys or values.
  • Verify that the redaction engine is correctly masking secure property values after the update by inspecting logs or performing a test deployment with sensitive data.

Generated by OpenCVE AI on September 19, 2026 at 00:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech hcl Devops Deploy
Hcltech hcl Launch
Vendors & Products Hcltech
Hcltech hcl Devops Deploy
Hcltech hcl Launch
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside insecure properties.
Title HCL DevOps Deploy / HCL Launch is susceptible to an Improper Removal of Sensitive Information Before Storage or Transfer
Weaknesses CWE-212
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Hcltech Hcl Devops Deploy Hcl Launch
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-09-18T20:07:37.150Z

Reserved: 2026-07-28T13:21:59.903Z

Link: CVE-2026-67071

cve-icon Vulnrichment

Updated: 2026-09-18T20:07:33.930Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T21:17:18.810

Modified: 2026-09-18T20:17:20.923

Link: CVE-2026-67071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:45:14Z

Weaknesses
  • CWE-212

    Improper Removal of Sensitive Information Before Storage or Transfer