PT-2026-96133 · Gocd · Gocd

CVE-2026-55060

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GoCD versions 13.1.0 through 26.0.0
Description The /go/api/support/process list endpoint fails to enforce administrator-only authorization. This allows an authenticated internal user to query the endpoint during the execution of source control child processes to view command-line arguments, usernames, remote material URLs, and internal material paths for materials they are not authorized to access. Exploitation is dependent on unpredictable process timing, although credentials, environment variables, and user-defined secrets remain masked or omitted.
Recommendations Update to version 26.1.0. Restrict access to the /go/api/support/process list endpoint to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55060
GHSA-VQJF-7PF8-HGWR

Affected Products

Gocd