SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-8339

HIGH · CVSS 8.7 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

A SQL injection vulnerability in the Coverity Connect SOAP API allows authenticated attackers to execute specially crafted payloads, potentially granting them full read access to sensitive database contents and the ability to perform unauthorized commands. Organizations using versions 2024.6.0 to 2026.3.0 should prioritize remediation to mitigate the risk of data exposure and unauthorized access. Immediate action is recommended for those managing sensitive data or critical applications relying on this API.

CVE
CVE-2026-8339
Severity
HIGH
CVSS
8.7
EPSS
0.20%

Original NVD Description

A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a specially crafted payload can achieve full read access to database contents and other unauthorized commands.