CVE Explorer
CVE-2026-1496
Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an authentication bypass. A malicious actor with access to the /token API endpoint that either knows or guesses a valid username, can use this in a specially crafted HTTP request to bypass authentication. Successful exploitation allows the malicious actor to assume all roles and privileges granted to the valid user’s Coverity Connect account.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Coverity","vendor":"Black Duck","versions":[{"lessThan":"2025.12.0","status":"affected","version":"2024.3.0","versionType":"custom"},{"status":"unaffected","version":"2024.3.0A"},{"status":"unaffected","version":"2024.3.1A"},{"status":"unaffected","version":"2024.3.2A"},{"status":"unaffected","version":"2024.6.0A"},{"status":"unaffected","version":"2024.6.1A"},{"status":"unaffected","version":"2024.9.0A"},{"status":"unaffected","version":"2024.9.1A"},{"status":"unaffected","version":"2024.12.0A"},{"status":"unaffected","version":"2024.12.1A"},{"status":…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:91f946785fa57dc4a0d4b3e8e8162076079bd4f35eec1653fca84324cf802de4 · sha256:04d50833a7f74cd9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpac…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:91f946785fa57dc4a0d4b3e8e8162076079bd4f35eec1653fca84324cf802de4 · sha256:04d50833a7f74cd9… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-639","description":"CWE-639 Authorization bypass through User-Controlled key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:91f946785fa57dc4a0d4b3e8e8162076079bd4f35eec1653fca84324cf802de4 · sha256:04d50833a7f74cd9… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"tags":["vendor-advisory"],"url":"https://community.blackduck.com/s/article/Black-Duck-Security-Advisory-CVE-2026-1496"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:91f946785fa57dc4a0d4b3e8e8162076079bd4f35eec1653fca84324cf802de4 · sha256:04d50833a7f74cd9… · /containers/cna/references/0
{"tags":["vendor-advisory","mitigation"],"url":"https://community.blackduck.com/s/article/Instructions-on-how-to-block-token-endpoint-for-Coverity-Connect"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:91f946785fa57dc4a0d4b3e8e8162076079bd4f35eec1653fca84324cf802de4 · sha256:04d50833a7f74cd9… · /containers/cna/references/1
{"tags":["vendor-advisory","mitigation"],"url":"https://community.blackduck.com/s/article/WAF-IDS-IPS-Mitigation-Guidance"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:91f946785fa57dc4a0d4b3e8e8162076079bd4f35eec1653fca84324cf802de4 · sha256:04d50833a7f74cd9… · /containers/cna/references/2
{"tags":["related"],"url":"https://github.com/blackduck-inc/Coverity-Usage-Log-Analyzer"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:91f946785fa57dc4a0d4b3e8e8162076079bd4f35eec1653fca84324cf802de4 · sha256:04d50833a7f74cd9… · /containers/cna/references/3
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.