{"id":"CVE-2026-67071","title":"HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values","summary":"HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the re…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-212"],"vendor":"HCLSoftware","product":"HCL DevOps Deploy / HCL Launch","affected":["hcl_devops_deploy_hcl_launch 7.3 - 7.3.2.20, 8.0 - 8.0.1.15, 8.1 - 8.1.2.8, 8.2 - 8.2.2.1"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T20:17:20.923","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-67071","references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133573","label":"psirt@hcl.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-18T20:07:28.109144Z"},"epss":0.00223,"epssPercentile":0.13096,"ingestedAt":"2026-09-17T21:29:16.984Z","slug":"CVE-2026-67071","body":"## Overview\n\nHCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside insecure properties.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}