At Black Duck, the security and integrity of our products is our highest priority. When that is compromised, we are committed to communicating as openly and proactively as possible. We recently identified a security vulnerability in Coverity Connect. Affected customers have already been notified and provided with comprehensive mitigation measures to address the issue.
On January 26, 2026, Black Duck received a report from Cenobe through our responsible disclosure program of a potential security vulnerability in Coverity® Static Analysis. Our Incident Response and Engineering teams immediately launched a thorough investigation, which confirmed the existence of a logic issue in the authentication controls within the Coverity Connect component.
This vulnerability, designated CVE-2026-1496, potentially allows unauthorized users to bypass established authentication controls and assume the roles and privileges of authorized Coverity users. The vulnerability is rated 9.3 (Critical) under CVSSv4 due to its theoretical worst-case impact. However, the actual risk exposure depends significantly on each customer’s specific deployment configuration.
Importantly, our investigation confirmed that this vulnerability is limited exclusively to Coverity Connect. It does not affect Coverity on Black Duck Polaris™ Platform or any other Black Duck products. Additionally, we have verified that exploiting this vulnerability does not create potential access to the Black Duck network or customer data on Black Duck systems. To date, Black Duck has no evidence to indicate that this vulnerability is under active exploitation.
Black Duck has moved swiftly to develop and deploy comprehensive mitigation measures for all affected customers. We understand that different organizations have different operational constraints, so we have created multiple mitigation pathways.
All patches, tools, documentation, and guidance can be found here.
We recommend that all Coverity Connect customers take the following steps:
Because Coverity is deployed on premises, any potential impact would be limited to data within your local Coverity instance. However, we strongly recommend ensuring that Coverity Connect is not made openly internet-accessible.
We recognize the trust placed in Black Duck to secure development environments, and we take that responsibility seriously. This notification reflects our policy of informing customers promptly, providing actionable mitigations, and maintaining open communication throughout the remediation process. For customers needing additional support, please work closely with your Black Duck account team or contact us at [email protected]. We will continue to keep you informed of any new developments.
Black Duck would like to recognize the professionalism of the Cenobe team. We appreciate their cooperation and ethical approach during the responsible disclosure process.
Mar 23, 2026 | 3 min read
Mar 16, 2026 | 5 min read
Feb 25, 2026 | 3 min read