CVE-2026-12084 PUBLISHED

IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains

Assigner: ibm
Reserved: 12.06.2026 Published: 30.06.2026 Updated: 01.07.2026

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS Score: 5.4

Product Status

Vendor IBM
Product UCD - IBM DevOps Deploy
Versions
  • affected from 8.1.0 to 8.1.2.6 (incl.)
  • affected from 8.2.0 to 8.2.1.0 (incl.)

Solutions

IBM strongly suggests the following:

Upgrade affected versions to any of 8.1.2.7 https://www.ibm.com/support/fixcentral/swg/downloadFixes , 8.2.2.0 https://www.ibm.com/support/fixcentral/swg/downloadFixes or later

References

Problem Types

  • CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains CWE