PT-2026-80890 · Unknown · Blackduck-C-Cpp
CVE-2026-76055
·
Published
2026-08-24
·
Updated
2026-08-24
CVSS v4.0
7.5
High
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
blackduck-c-cpp versions prior to 3.0.7
Description
The package manager component contains a flaw where filesystem paths encountered during directory traversal are interpolated into command strings executed through a shell without proper quoting or escaping. This allows an actor capable of creating a file within the scanned build directory to execute operating system commands with the privileges of the account running the scan. This occurs because shell metacharacters within the paths are interpreted as commands rather than literal text, requiring no control over the build command or tool configuration.
Recommendations
Update blackduck-c-cpp to version 3.0.7 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blackduck-C-Cpp