CVEPublished 2026-08-24Modified 2026-09-010 articles on news6 live referencesNVD data

CVE-2026-76054

Vulnerability data via NVD (ingested)

CVSS v3.1
EPSS percentile
3
Exploit Prediction Scoring System · top 97% of all CVEs
Description

Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's build to obtain the Black Duck API token via the ambient process environment, which is inherited by subprocesses launched during build capture and signature scanning. This applies only where the token is supplied through the BLACKDUCK_API_TOKEN or BD_HUB_TOKEN environment variable. Upgrading does not remediate prior disclosure; any token supplied to an affected version through an environment variable should be rotated.

Timeline
Published 2026-08-24
Modified 2026-09-01

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub

No public proof-of-concept repositories found for CVE-2026-76054 on GitHub.
We haven't classified any articles referencing CVE-2026-76054 yet. The external references above still apply.