Sonar Launches SonarQube Hunter Agent to Catch Logic-based Security Flaws

Sonar Launches SonarQube Hunter Agent to Catch Logic-based Security Flaws

PR Newswire

New AI security agent finds the broken access control, business-logic, and authentication vulnerabilities pattern-based scanning was never built to catch, in the SonarQube workflow teams already use

AUSTIN, Texas, Aug. 27, 2026 /PRNewswire/ — Sonar, a global leader in AI code verification and governance, today announced the general availability of SonarQube Hunter Agent, an AI-powered security agent built to catch high-impact vulnerabilities that traditional pattern-based scanning was never designed to find.

SonarQube Hunter Agent

Closing the gap

Deterministic scanning is excellent at catching flaws that look wrong in the code, including injection vulnerabilities, unsafe data flows, and insecure patterns. However, some vulnerabilities aren’t detectable in the code itself; they’re visible only when you understand what the code is supposed to do. Examples include things like a user who can view another customer’s records, a checkout flow that can be skipped, or a session that doesn’t expire the way it should. In these examples, the code technically runs exactly as written, but it permits something it was never meant to allow.

Traditionally, identifying these types of issues required manual security review or a penetration test. Both of these options are expensive, slow, and ultimately out of date the moment new code ships. As AI-assisted development accelerates the pace of shipping code, the window between release and exploitation is shrinking fast. Catching issues before code ships is now essential to staying ahead of the attackers.

What Hunter Agent does

SonarQube Hunter Agent analyzes a project’s entire codebase to find three categories of flaws that require reasoning, not pattern-matching: broken access control, business-logic vulnerabilities, and authentication or session-management issues.

The agent works the way a human security researcher would, by tracing how code, data, and identity move through a system, then investigating and confirming each candidate issue before it ever reaches a developer. Verified findings land directly inside the SonarQube workflow, next to the rest of a team’s issues. This means that security and development teams triage, assign, and track without learning a new tool or switching context.

Because it runs in the background, on a set schedule or on demand, SonarQube Hunter Agent never blocks a pull request or slows down CI/CD. Further, as every finding is confirmed before it surfaces, teams spend their time on real risk instead of sorting through noise.

SonarQube Hunter Agent is designed to complement SonarQube’s existing SAST, not replace it, extending Sonar’s zero-trust, multilayered verification philosophy. It plugs the logic flaw blind spot SAST was never designed to cover. Where SAST catches flaws in how code is written, Hunter Agent catches the flaws in what code is meant to do.

Why it matters

“AI is changing not only the speed of software development, but also the scale of the verification challenge,” said Johannes Dahse, VP of Code Security at Sonar. “SonarQube Hunter Agent helps teams identify the security flaws that require reasoning about what code is meant to do, not just how it’s written. By bringing those findings into the SonarQube workflow, we give security and development teams a practical way to extend verification as the pace of AI-driven development increases.”

Unlike vendor-coupled AI review tools, blackbox pentest agents that probe a live target from the outside, or point-in-time manual audits, SonarQube Hunter Agent is an independent, verification layer that inspects the full codebase continuously and gives teams accurate findings they can trust and track over time — turning what used to be a periodic audit into a standing capability.

Availability

SonarQube Hunter Agent is generally available today for SonarQube Cloud, with support for SonarQube Server coming soon. Learn more at  sonarsource.com/products/sonarqube/hunter-agent.

About Sonar

Sonar, a global leader in AI code verification and governance, helps reduce outages, improve security, and lower costs and risks associated with AI and agentic coding. As a zero-trust, multilayered verification platform, Sonar enables organizations to securely develop at the speed of AI, and with the addition of Gitar’s AI-native code review, offers the most comprehensive way to verify code in the agentic era. A Leader in the Gartner® Magic Quadrant™ for Technical Debt Management Tools¹, Sonar delivers the foundation for the AI enterprise software factory—analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at Nvidia, ServiceNow, Booking.com, Goldman Sachs, AstraZeneca, and Ford Motor Company.

To learn more about Sonar, please visit: www.sonar.com

Cautionary note: Forward-looking statements

This press release may contain forward-looking statements about future expectations, plans, and prospects. These statements are based on current beliefs and assumptions and are subject to risks and uncertainties. The information in this press release is provided as of this date, and we undertake no obligation to update any statements.

¹Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

Sonar Logo

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/sonar-launches-sonarqube-hunter-agent-to-catch-logic-based-security-flaws-302861444.html

SOURCE Sonar