CVE-2026-8338: Black Duck Coverity Connect
Critical severity, CVSS 9.2. EPSS: 0.5% chance of exploitation in the next 30 days.
A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data within Coverity.
Affected products
- Black Duck Coverity Connect: from 2023.6.0, before 2026.6.0 (fixed in 2026.6.0)
Published 2026-07-29. Last modified 2026-07-30.