CVE-2026-8338 Details
Description
A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data within Coverity.
A vulnerability allowing authentication and authorization bypass has been identified in Coverity Connect versions 2023.6.0 prior to 2026.3.0. This issue arises from a flaw in Spring Security, where an unauthenticated malicious actor can send a specially crafted HTTP request to bypass authentication and authorization controls on certain API endpoints, potentially leading to unauthorized access to data within Coverity.
Users should upgrade to Coverity Connect version 2026.6.0 or later. Instructions for upgrading can be found in the Coverity documentation on supported versions and compatibility.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.blackduck.com/s/article/Black-Duck-Product-Security-Advisory-CVE-2026-8338-Authentication-and-Authorization-Bypass | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 29, 2026 | CVE Modified | CISA-ADP |
| Jul 29, 2026 | New CVE Received | [email protected] |