CVE 9.3 CRITICAL

Coverity CLI Authentication Bypass_CVE-2026-1496

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an authentication bypass. A malicious actor with access to the /token API endpoint that either knows or guesses a valid username, can use this in a specially crafted HTTP request to bypass authentication. Successful exploitation allows the malicious actor to assume all roles and privileges granted to the valid user’s Coverity Connect account.

Basic Information

ID CVE-2026-1496
Source BlackDuck
Published Mar 27, 2026 at 14:14
Modified Mar 27, 2026 at 14:36

Affected Product

Vendor Black Duck
Product Coverity
Version 2024.3.0
Affected Versions Black Duck Coverity 2024.3.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.