CVE-2026-8339: SQL Injection in Coverity Connect SOAP API
Published Jul 29, 2026
·Updated
A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a specially crafted payload can achieve full read access to database contents and other unauthorized commands.
Affected Software
1 affected component
Synopsys Coverity Connect SOAP API>=2024.6.0<=2026.3.0
Event History
Jul 29, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-8339?
CVE-2026-8339 has a high severity rating of 8.7.
2
What type of vulnerability is CVE-2026-8339?
CVE-2026-8339 is a SQL Injection vulnerability.
3
Which software versions are affected by CVE-2026-8339?
CVE-2026-8339 affects Synopsys Coverity Connect SOAP API versions between 2024.6.0 and 2026.3.0.
4
How can CVE-2026-8339 be exploited?
CVE-2026-8339 can be exploited by a malicious authenticated user who sends a specially crafted payload.
5
What impact does CVE-2026-8339 have?
CVE-2026-8339 allows attackers to gain full read access to database contents and execute unauthorized commands.