Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-1496 1 Black Duck 1 Coverity 2026-03-27 N/A
Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an authentication bypass. A malicious actor with access to the /token API endpoint that either knows or guesses a valid username, can use this in a specially crafted HTTP request to bypass authentication. Successful exploitation allows the malicious actor to assume all roles and privileges granted to the valid user’s Coverity Connect account.