Description
A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data within Coverity.
Published: 2026-07-29
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Spring Security authentication and authorization bypass exists in Coverity Connect that allows an unauthenticated attacker to send a specially crafted HTTP request and gain access to data within the platform. The flaw permits bypassing both authentication checks and authorization controls on specific API endpoints, resulting in an unauthorized disclosure of potentially sensitive information. The weakness relies on a flaw in the handling of authentication headers and request validation, categorized as authentication bypass by spoofing (CWE‑288).

Affected Systems

Black Duck:Coverity Connect versions between 2023.6.0 and 2026.3.0 are affected by the vulnerability. Users running any release in that range must update to a patched version or beyond 2026.3.0 to remove the flaw.

Risk and Exploitability

The CVSS score of 9.2 indicates a high severity, while the EPSS score of less than 1% suggests the exploitation likelihood is currently low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is an unauthenticated attacker sending a specially crafted HTTP request to the target API endpoints, implying that a network actor—potentially on the same local network or with external access to the Coverity Connect service—could leverage this bypass. No additional privileged access or system compromise is required to exploit the flaw.

Generated by OpenCVE AI on August 4, 2026 at 12:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Coverity Connect to a released version newer than 2026.3.0 that contains the vendor patch.
  • Verify that all API endpoints enforce proper authentication and authorization settings, ensuring that no legacy or unprotected routes remain exposed.
  • Restrict network access to Coverity Connect’s API endpoints using firewall rules or subnet isolation to limit the attack surface to trusted hosts only.

Generated by OpenCVE AI on August 4, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Black Duck
Black Duck coverity
Vendors & Products Black Duck
Black Duck coverity

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data within Coverity.
Title Authentication and Authorization Bypass in Coverity Connect
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Black Duck Coverity
cve-icon MITRE

Status: PUBLISHED

Assigner: BlackDuck

Published:

Updated: 2026-07-29T18:06:23.447Z

Reserved: 2026-05-11T16:05:30.569Z

Link: CVE-2026-8338

cve-icon Vulnrichment

Updated: 2026-07-29T18:06:20.583Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-29T17:16:54.177

Modified: 2026-07-30T19:07:59.843

Link: CVE-2026-8338

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:30:09Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel