PT-2026-96132 · Gocd · Gocd

CVE-2026-52742

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions GoCD versions 12.3.1 through 26.0.x
Description Legacy routes under the endpoint '/go/admin/restful/*' expose the full historical server configuration to pipeline group administrators. This occurs because the system fails to restrict responses to only the configuration of groups they are authorized to administer. The exposed data may include agent auto-registration keys, webhook invocation keys, encrypted material credentials, and lists of GoCD administrators. A malicious pipeline group administrator could utilize the agent registration data to connect an unauthorized compatible agent, potentially allowing them to receive work or overwrite artifacts belonging to other groups.
Recommendations Update to version 26.1.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52742
GHSA-7XXX-FV46-VP7H

Affected Products

Gocd