Improper Neutralization Vulnerability in Black Duck Package Manager Component
CVE-2026-76055

7.5HIGH

Key Information:

Vendor

Black Duck

Vendor
CVE Published:
24 August 2026

What is CVE-2026-76055?

The vulnerability in the Black Duck package manager component occurs due to improper neutralization of special elements in filesystem paths. When an actor is able to create a file in the scanned build directory, they can potentially execute arbitrary operating system commands via shell metacharacters. The lack of quoting or escaping allows these characters in the filesystem paths to be treated as commands rather than literal text. Consequently, this flaw poses significant security risks as it permits unauthorized command execution without requiring control over the build command or configuration settings.

Affected Version(s)

blackduck-c-cpp 0 < 3.0.7

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.