CVE-2026-76054 PUBLISHED

Assigner: BlackDuck
Reserved: 18.08.2026 Published: 24.08.2026 Updated: 24.08.2026

Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's build to obtain the Black Duck API token via the ambient process environment, which is inherited by subprocesses launched during build capture and signature scanning. This applies only where the token is supplied through the BLACKDUCK_API_TOKEN or BD_HUB_TOKEN environment variable.

Upgrading does not remediate prior disclosure; any token supplied to an affected version through an environment variable should be rotated.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:L
CVSS Score: 7.1

Product Status

Vendor Black Duck
Product blackduck-c-cpp
Versions Default: unaffected
  • affected from 1.0.17 to 3.0.7 (excl.)

Credits

  • NVIDIA finder

References

Problem Types

  • CWE-214 Invocation of Process Using Visible Sensitive Information CWE

Impacts

  • Disclosure of the Black Duck API token to processes running on the host performing the scan. The token authenticates to the Black Duck instance and, in the configuration documented as the minimum for scanning to a new project, permits reading all projects, Bills of Materials, and code locations on that instance and creating, modifying, or deleting projects, versions, and code locations.