What is CVE-2026-8338?
CVE-2026-8338 is an authentication and authorization bypass in Coverity Connect's Spring Security. An unauthenticated attacker can send a specially crafted HTTP request to gain unauthorized access to certain API endpoints. Affected systems should be patched immediately or network-level restrictions should be applied temporarily.
Azərbaycanca: CVE-2026-8338, Coverity Connect-in Spring Security autentifikasiya və avtorizasiya mexanizmində boşluqdur. Təsdiqlənməmiş hücumçu xüsusi HTTP sorğusu göndərərək müəyyən API-lərə icazəsiz giriş əldə edə bilər. Ən qısa zamanda yamaq tətbiq edilməli və ya müvəqqəti olaraq şəbəkə səviyyəsində məhdudiyyətlər qoyulmalıdır.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which component of Coverity Connect does CVE-2026-8338 affect?
This vulnerability affects the Spring Security authentication and authorization mechanism in Coverity Connect.
What can an attacker achieve by exploiting CVE-2026-8338?
An unauthenticated attacker can send a specially crafted HTTP request to gain unauthorized access to certain API endpoints.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.