PT-2026-96130 · Gocd · Gocd
CVE-2026-52740
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GoCD versions 18.7.0 through 26.0.x
Description
The Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. This allows an authenticated user with low privileges to bypass view permission requirements and read the configuration of a pipeline template by sending a request with nonstandard HTTP method capitalization. This issue does not affect API operations that modify data, and secure variables remain encrypted.
Recommendations
Update to version 26.1.0.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gocd