PT-2026-96133 · Gocd · Gocd
CVE-2026-55060
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GoCD versions 13.1.0 through 26.0.0
Description
The
/go/api/support/process list endpoint fails to enforce administrator-only authorization. This allows an authenticated internal user to query the endpoint during the execution of source control child processes to view command-line arguments, usernames, remote material URLs, and internal material paths for materials they are not authorized to access. Exploitation is dependent on unpredictable process timing, although credentials, environment variables, and user-defined secrets remain masked or omitted.Recommendations
Update to version 26.1.0.
Restrict access to the
/go/api/support/process list endpoint to minimize the risk of exploitation.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gocd