Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76054

Quick assessment

Affected
Black Duck blackduck-c-cpp
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

黑盾(Black Duck)blackduck-c-cpp 1.0.17 至 3.0.6 版本中,由于在进程中使用了可见的敏感信息,存在安全隐患。攻击者若能在被扫描项目的构建环境中执行代码,即可通过子进程继承的环境变量获取 Black Duck API 令牌。这些子进程是在构建捕获和签名扫描期间启动的。此问题仅在通过 或 环境变量提供令牌时适用。 升级并不能补救已泄露的令牌;因此,对于受影响的版本,通过环境变量提供的所有令牌都应重新生成(轮换)。

CVSS 7.1 · High

Possible ATT&CK Techniques 1 AI

T1098.004 · SSH Authorized Keys
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76054

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's build to obtain the Black Duck API token via the ambient process environment, which is inherited by subprocesses launched during build capture and signature scanning. This applies only where the token is supplied through the BLACKDUCK_API_TOKEN or BD_HUB_TOKEN environment variable. Upgrading does not remediate prior disclosure; any token supplied to an affected version through an environment variable should be rotated.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:L
Source: CVE Program / CVE List V5
Vulnerability Type
通过处理环境导致的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Black Duck blackduck-c-cpp 1.0.17 ~ 3.0.7 -

II. Public POCs for CVE-2026-76054

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-76054

登录查看更多情报信息。

Vendor Advisories for CVE-2026-76054 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-76054

No comments yet


Leave a comment