PT-2026-96132 · Gocd · Gocd
CVE-2026-52742
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
GoCD versions 12.3.1 through 26.0.x
Description
Legacy routes under the endpoint '/go/admin/restful/*' expose the full historical server configuration to pipeline group administrators. This occurs because the system fails to restrict responses to only the configuration of groups they are authorized to administer. The exposed data may include agent auto-registration keys, webhook invocation keys, encrypted material credentials, and lists of GoCD administrators. A malicious pipeline group administrator could utilize the agent registration data to connect an unauthorized compatible agent, potentially allowing them to receive work or overwrite artifacts belonging to other groups.
Recommendations
Update to version 26.1.0.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gocd