Sensitive Information Exposure in Black Duck by Synopsys
CVE-2026-76054

7.1HIGH

Key Information:

Vendor

Black Duck

Vendor
CVE Published:
24 August 2026

What is CVE-2026-76054?

This vulnerability allows unauthorized actors to access sensitive API tokens in Black Duck's blackduck-c-cpp versions 1.0.17 through 3.0.6. The issue arises when these tokens are supplied via environment variables, enabling them to be inherited by subprocesses during build captures and signature scanning. This exposure poses a significant risk to the confidentiality of the API token. It is crucial that any tokens supplied to affected versions be rotated to mitigate the potential for unauthorized access.

Affected Version(s)

blackduck-c-cpp 1.0.17 < 3.0.7

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NVIDIA
.