CVE Database
/

CVE-2026-1496

Back to search

CVE-2026-1496

Published: Mar 27, 2026

Modified: Mar 27, 2026

PUBLISHED

Description

Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an authentication bypass. A malicious actor with access to the /token API endpoint that either knows or guesses a valid username, can use this in a specially crafted HTTP request to bypass authentication. Successful exploitation allows the malicious actor to assume all roles and privileges granted to the valid user’s Coverity Connect account.

VendorProductVersions

Black Duck

Coverity

affected
2024.3.0 - < 2025.12.0
unaffected
2024.3.0A
unaffected
2024.3.1A
unaffected
2024.3.2A
unaffected
2024.6.0A

+17 more versions

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2026-1496 - Security Vulnerability | QwikSec