๐Ÿ” CVE Alert

CVE-2026-8339

UNKNOWN 0.0

SQL Injection in Coverity Connect SOAP API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a specially crafted payload can achieve full read access to database contents and other unauthorized commands.

CWE CWE-89
Vendor black duck
Product coverity connect
Published Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for black duck coverity connect

Be the first to know when new unknown vulnerabilities affecting black duck coverity connect are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Black Duck / Coverity Connect
2024.6.0 < 2026.6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
community.blackduck.com: https://community.blackduck.com/s/article/Black-Duck-Product-Security-Advisory-CVE-2026-8339-SQL-Injection-Vulnerability-in-Coverity-Connect-SOAP-API