CVE-2026-67071

HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside insecure properties.

  • Published Sep 17, 2026
  • CVSS 6.5 medium
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-67071 at the National Vulnerability Database