---
id: CVE-2026-56457
title: >-
  HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive
  information vulnerability in output logs
summary: >-
  HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive
  information vulnerability in output logs. This exposure could allow an
  attacker with access to the logs to potentially obtain sensitive values
  related to that step.
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-532
vendor: hcltechsw
product: hcl_devops_deploy
affected:
  - 'hcl_devops_deploy >= 8.0.0.0, < 8.0.1.14'
  - 'hcl_devops_deploy >= 8.1.0.0, < 8.1.2.7'
  - 'hcl_devops_deploy >= 8.2.0.0, < 8.2.2.0'
  - 'hcl_launch >= 7.3.0.0, < 7.3.2.19'
patched:
  - hcl_devops_deploy 8.2.2.0
  - hcl_launch 7.3.2.19
published: '2026-06-29'
updated: '2026-07-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56457'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131694
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00301
epssPercentile: 0.20383
ingestedAt: '2026-07-03T13:02:28.090Z'
---

## Overview

HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step.

## Affected

- `hcl_devops_deploy >= 8.0.0.0, < 8.0.1.14`
- `hcl_devops_deploy >= 8.1.0.0, < 8.1.2.7`
- `hcl_devops_deploy >= 8.2.0.0, < 8.2.2.0`
- `hcl_launch >= 7.3.0.0, < 7.3.2.19`

## Remediation

Upgrade past the affected range:

- `hcl_devops_deploy 8.2.2.0`
- `hcl_launch 7.3.2.19`
