CVE-2026-8339: Black Duck Coverity Connect

High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.

A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a specially crafted payload can achieve full read access to database contents and other unauthorized commands.

Affected products

  • Black Duck Coverity Connect: from 2024.6.0, before 2026.6.0 (fixed in 2026.6.0)

Published 2026-07-29. Last modified 2026-07-30.