Sensitive Information Exposure in Black Duck by Synopsys
CVE-2026-76054
7.1HIGH
What is CVE-2026-76054?
This vulnerability allows unauthorized actors to access sensitive API tokens in Black Duck's blackduck-c-cpp versions 1.0.17 through 3.0.6. The issue arises when these tokens are supplied via environment variables, enabling them to be inherited by subprocesses during build captures and signature scanning. This exposure poses a significant risk to the confidentiality of the API token. It is crucial that any tokens supplied to affected versions be rotated to mitigate the potential for unauthorized access.
Affected Version(s)
blackduck-c-cpp 1.0.17 < 3.0.7
