Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76055

Quick assessment

Affected
Black Duck blackduck-c-cpp
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Black Duck blackduck-c-cpp 3.0.7 之前版本中的包管理器组件存在操作系统命令特殊元素未正确中和的漏洞。该漏洞允许攻击者在扫描构建目录内创建文件后,以执行扫描的账户身份执行操作系统命令。 在遍历扫描目录时遇到的文件系统路径会被插值到通过 shell 执行的命令字符串中,且未进行引号包裹或转义处理,因此这些路径中的 shell 元字符会被解释为命令执行的一部分,而非作为纯文本处理。此漏洞无需对构建命令或工具配置拥有任何控制权即可被利用。

CVSS 7.5 · High EPSS 0.13% · P3

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 1

VendorProduct Version RangeStatus
Black Duck blackduck-c-cpp < 3.0.7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76055

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackduck-c-cpp before 3.0.7 allows an actor able to create a file within the scanned build directory to execute operating system commands as the account running the scan. Filesystem paths encountered while traversing the scanned directory are interpolated into command strings that are executed through a shell without quoting or escaping, so shell metacharacters within those paths are interpreted rather than treated as literal text. No control over the build command or the tool's configuration is required.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Black Duck blackduck-c-cpp 0 ~ 3.0.7 -

II. Public POCs for CVE-2026-76055

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-76055

登录查看更多情报信息。

Vendor Advisories for CVE-2026-76055 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-76055

No comments yet


Leave a comment