CVE-2026-8338: Black Duck Coverity Connect

Critical severity, CVSS 9.2. EPSS: 0.5% chance of exploitation in the next 30 days.

A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data within Coverity.

Affected products

  • Black Duck Coverity Connect: from 2023.6.0, before 2026.6.0 (fixed in 2026.6.0)

Published 2026-07-29. Last modified 2026-07-30.