---
id: CVE-2026-56460
title: >-
  HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and
  secrets to authenticated users in API responses that could be used in further
  attacks against the system.
summary: >-
  HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and
  secrets to authenticated users in API responses that could be used in further
  attacks against the system.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-201
vendor: hcltechsw
product: hcl_devops_deploy
affected:
  - 'hcl_devops_deploy >= 8.0.0.0, < 8.0.1.14'
  - 'hcl_devops_deploy >= 8.1.0.0, < 8.1.2.7'
  - 'hcl_devops_deploy >= 8.2.0.0, < 8.2.2.0'
  - 'hcl_launch >= 7.3.0.0, < 7.3.2.19'
patched:
  - hcl_devops_deploy 8.2.2.0
  - hcl_launch 7.3.2.19
published: '2026-07-09'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56460'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131697
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00379
epssPercentile: 0.29113
ingestedAt: '2026-07-13T13:27:18.227Z'
---

## Overview

HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.

## Affected

- `hcl_devops_deploy >= 8.0.0.0, < 8.0.1.14`
- `hcl_devops_deploy >= 8.1.0.0, < 8.1.2.7`
- `hcl_devops_deploy >= 8.2.0.0, < 8.2.2.0`
- `hcl_launch >= 7.3.0.0, < 7.3.2.19`

## Remediation

Upgrade past the affected range:

- `hcl_devops_deploy 8.2.2.0`
- `hcl_launch 7.3.2.19`
