CVE-2026-8338
Authentication and Authorization Bypass in Coverity Connect
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data within Coverity.
| CWE | CWE-288 |
| Vendor | black duck |
| Product | coverity connect |
| Published | Jul 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for black duck coverity connect
Be the first to know when new unknown vulnerabilities affecting black duck coverity connect are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Black Duck / Coverity Connect
2023.6.0 < 2026.6.0