Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's build to obtain the Black Duck API token via the ambient process environment, which is inherited by subprocesses launched during build capture and signature scanning. This applies only where the token is supplied through the BLACKDUCK_API_TOKEN or BD_HUB_TOKEN environment variable.



Upgrading does not remediate prior disclosure; any token supplied to an affected version through an environment variable should be rotated.

Project Subscriptions

Vendors Products
Black Duck Subscribe
Blackduck-c-cpp Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title API Token Exposure via Build Process in Black Duck blackduck-c-cpp
First Time appeared Black Duck
Black Duck blackduck-c-cpp
Vendors & Products Black Duck
Black Duck blackduck-c-cpp

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's build to obtain the Black Duck API token via the ambient process environment, which is inherited by subprocesses launched during build capture and signature scanning. This applies only where the token is supplied through the BLACKDUCK_API_TOKEN or BD_HUB_TOKEN environment variable. Upgrading does not remediate prior disclosure; any token supplied to an affected version through an environment variable should be rotated.
Weaknesses CWE-214
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: BlackDuck

Published:

Updated: 2026-08-24T15:00:34.809Z

Reserved: 2026-08-18T20:17:15.954Z

Link: CVE-2026-76054

cve-icon Vulnrichment

Updated: 2026-08-24T15:00:28.065Z

cve-icon NVD

Status : Received

Published: 2026-08-24T15:16:46.650

Modified: 2026-08-24T15:16:46.650

Link: CVE-2026-76054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:15:07Z

Weaknesses