PT-2026-96130 · Gocd · Gocd

CVE-2026-52740

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GoCD versions 18.7.0 through 26.0.x
Description The Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. This allows an authenticated user with low privileges to bypass view permission requirements and read the configuration of a pipeline template by sending a request with nonstandard HTTP method capitalization. This issue does not affect API operations that modify data, and secure variables remain encrypted.
Recommendations Update to version 26.1.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52740
GHSA-9JFM-4F6V-79WH

Affected Products

Gocd