SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-8338

CRITICAL · CVSS 9.2 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Coverity Connect versions from 2023.6.0 to 2026.3.0 are vulnerable to an authentication and authorization bypass due to a flaw in Spring Security, allowing unauthenticated attackers to exploit specific API endpoints. This vulnerability enables unauthorized access to sensitive data, posing a significant risk to organizations using these versions. Organizations utilizing Coverity Connect should prioritize patching this vulnerability to safeguard their data integrity and security.

CVE
CVE-2026-8338
Severity
CRITICAL
CVSS
9.2
EPSS
0.30%

Original NVD Description

A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data within Coverity.