The CVE-2026-76055 vulnerability is classified as Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackduck-c-cpp before 3.0.7. This vulnerability allows an actor able to create a file within the scanned build directory to execute operating system commands as the account running the scan. The vulnerability has a CVSS score of 7.5 and a sever [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-24T15:16:46.650Z and has not been modified since then. The Black Duck blackduck-c-cpp package is vulnerable to sensitive information disclosure. An actor able to execute code within the scanned project's build can obtain the Black Duck API token via the ambient process environment. This applies only [truncated]